Re: Question regarding tacacs

From: Sadiq Yakasai <sadiqtanko_at_gmail.com>
Date: Wed, 21 Apr 2010 11:56:32 +0100

If you change the IP address of the TACACS interface, that will effectively
make the device unknown to ACS. This means that the next time you try to
authenticate (and get access to the device in question), it will not have
connectivity to the AAA server.

I dont think this will affect authenticated sessions on the device though.
So if you are logged in, you wont be booted off the box. So you can have a
chance to make all necessary corrections before your 'resignation letter"
comes along... :-)

On Wed, Apr 21, 2010 at 11:04 AM, Naufal Jamal <naufalccie_at_yahoo.in> wrote:

>
> Hi,
>
> I have the command ip tacacs source-interface g1/0 in my router. now i want
> to
> change the ip address of g1/0. would it cause any lockdown as i could
> access
> it remotely only through tacacs only. shuld i advrtise the new subnet first
> and then change the source-interface? any other way to save my job :) i am
> accessing it through loopback 0 interface.
>
> Thank you,
> Naufal Jamal
>
>
> Blogs and organic groups at http://www.ccie.net
>
> _______________________________________________________________________
> Subscription information may be found at:
> http://www.groupstudy.com/list/CCIELab.html
>
>
>
>
>
>
>
>

-- 
CCIE #19963
Blogs and organic groups at http://www.ccie.net
Received on Wed Apr 21 2010 - 11:56:32 ART

This archive was generated by hypermail 2.2.0 : Sat May 01 2010 - 09:49:57 ART