NetApp - Brocade Fabric OS TACACS+ authentication
NetApp Solution · Config document · referenced from Access and directory integration
The Fabric OS commands that make a Brocade 6505 authenticate logins against two TACACS+ servers first and against its local user database second.
| Item | Value |
|---|---|
| Runs on | Fabric OS command line of each FC switch, as admin |
| Shown here | one switch; the commands are identical on all of them |
| Also applied to | DC1-A-SNAS001, DC1-A-SNAS002, DC1-B-SNAS001, DC1-B-SNAS002, and the four switches of site 2 by the design |
| TACACS+ servers | 10.11.17.17, 10.11.17.19, port 49 |
| Fabric OS version | 8.0.1, by the administration guide the notes refer to |
The command set
# Show the AAA configuration before the change # (expected: no RADIUS, LDAP or TACACS+ configuration, # "Primary AAA Service: Switch database") aaaconfig --show # Add the first and the second TACACS+ server, authentication protocol PAP aaaconfig --add 10.11.17.17 -conf tacacs+ -s <TACACS_SHARED_SECRET> -a pap aaaconfig --add 10.11.17.19 -conf tacacs+ -s <TACACS_SHARED_SECRET> -a pap # Authenticate against TACACS+ first, the local switch database second; # -nologout keeps the current sessions open aaaconfig --authspec "tacacs+;local" -nologout # Show the result # (expected: two servers, port 49, timeout 3 s, Auth-Protocol PAP, # "Primary AAA Service: TACACS+", "Secondary AAA Service: Switch database") aaaconfig --show
What is not here
The server side is missing from the Source material: the stanza on the TACACS+ servers that authenticates the user against Active Directory and returns the Fabric OS role for the administrator and operator groups. The timeout of 3 seconds and port 49 are defaults; they were not set.
The LDAP configuration that was tried before and removed (aaaconfig --add … -conf ldap, ldapcfg --maprole) is described in the Article and is not part of the final state.
Checked against Fabric OS 9.2.x
| As built | Today |
|---|---|
| Brocade 6505 | End of support was 30 April 2025; Fabric OS releases that went GA after 30 April 2023 are not available for it |
| Fabric OS 8.0.1 | End of support for 8.0.x was 30 July 2020. Current streams are 9.2.x and 10.0.x |
aaaconfig --add <server> -conf tacacs+ -s <secret> -a pap | Same syntax in 8.2.x and 9.2.x, with -a chap or pap and an added -e none or aes256. With -e aes256 the shared secret is stored encrypted, with none in plain text |
aaaconfig --authspec "tacacs+;local" -nologout | Unchanged |
aaaconfig --add … -conf ldap -p 389 (the abandoned attempt) | Valid, and 8.2.x and 9.2.x add -tls_mode starttls or ldaps |
userconfig --change root -e yes, rootaccess --set all | From Fabric OS 9.1.1 there is no accessible root account. In versions that have one it is disabled by default and reachable over the serial console only |
Today the choice would be -a chap and -e aes256. Whether Fabric OS 8.0.1 already had -e aes256 and -tls_mode could not be confirmed.