Switches, Hubs, and Modems
1753469 Members
4998 Online
108794 Solutions
New Discussion юеВ

Re: Configuration help for : Procurve 2524,ssh,tacacs and enable mode - needed

 
Holger Graulich
New Member

Configuration help for : Procurve 2524,ssh,tacacs and enable mode - needed

Hi all,

the login login to a Procure 2524 via ssh and tacacs is working well, but I am not able to switch to the enable mode automatic.

On Procurve 2626, 2650 for example it works with "aaa authentication login privilege-mode", but this command is not present on the 2524.

The following is configured at the moment for aaa authentivation:
1. aaa authentication console login tacacs local
2. aaa authentication telnet login tacacs local
3. aaa authentication ssh login tacacs local


Any idea?
2 REPLIES 2
Jeff Carrell
Honored Contributor

Re: Configuration help for : Procurve 2524,ssh,tacacs and enable mode - needed

it is different for the 2524:

from the F_05_55 relnotes:

Note on Privilege Levels:
When a TACACS+ server authenticates an access request from a switch, it includes a privilege level code for the switch to use in determining which privilege level to grant to the terminal requesting access. The switch interprets a privilege level code of "15" as authorization for the Manager (read/write) privilege level access. Privilege level codes of 14 and lower result in Operator (read-only) access. Thus, when configuring the TACACS+ server response to a request that includes a username/password pair that should have Manager privileges, you must use a privilege level of 15. For more on this topic, refer to the documentation you received with your TACACS+ server application.

hth...jeff
Holger Graulich
New Member

Re: Configuration help for : Procurve 2524,ssh,tacacs and enable mode - needed

Thank you for the quick answer. I will have a look and ask the Tacacs Admin.