LINUXOR.SK ... open source notes ...

NetApp - Brocade Fabric OS TACACS+ authentication

category: solutionz · date: 2019-12-31 · updated: 2026-10-02 · author: LALA

NetApp Solution · Config document · referenced from Access and directory integration

noteThe shared secret is a placeholder. On the switch it is given on the command line, so it lands in the session history of whoever types it. PAP sends the password to the TACACS+ server protected only by that shared secret.

The Fabric OS commands that make a Brocade 6505 authenticate logins against two TACACS+ servers first and against its local user database second.

ItemValue
Runs onFabric OS command line of each FC switch, as admin
Shown hereone switch; the commands are identical on all of them
Also applied toDC1-A-SNAS001, DC1-A-SNAS002, DC1-B-SNAS001, DC1-B-SNAS002, and the four switches of site 2 by the design
TACACS+ servers10.11.17.17, 10.11.17.19, port 49
Fabric OS version8.0.1, by the administration guide the notes refer to

The command set

bash
# Show the AAA configuration before the change
# (expected: no RADIUS, LDAP or TACACS+ configuration,
#  "Primary AAA Service: Switch database")
aaaconfig --show

# Add the first and the second TACACS+ server, authentication protocol PAP
aaaconfig --add 10.11.17.17 -conf tacacs+ -s <TACACS_SHARED_SECRET> -a pap
aaaconfig --add 10.11.17.19 -conf tacacs+ -s <TACACS_SHARED_SECRET> -a pap

# Authenticate against TACACS+ first, the local switch database second;
# -nologout keeps the current sessions open
aaaconfig --authspec "tacacs+;local" -nologout

# Show the result
# (expected: two servers, port 49, timeout 3 s, Auth-Protocol PAP,
#  "Primary AAA Service: TACACS+", "Secondary AAA Service: Switch database")
aaaconfig --show

What is not here

The server side is missing from the Source material: the stanza on the TACACS+ servers that authenticates the user against Active Directory and returns the Fabric OS role for the administrator and operator groups. The timeout of 3 seconds and port 49 are defaults; they were not set.

The LDAP configuration that was tried before and removed (aaaconfig --add … -conf ldap, ldapcfg --maprole) is described in the Article and is not part of the final state.

Checked against Fabric OS 9.2.x

As builtToday
Brocade 6505End of support was 30 April 2025; Fabric OS releases that went GA after 30 April 2023 are not available for it
Fabric OS 8.0.1End of support for 8.0.x was 30 July 2020. Current streams are 9.2.x and 10.0.x
aaaconfig --add <server> -conf tacacs+ -s <secret> -a papSame syntax in 8.2.x and 9.2.x, with -a chap or pap and an added -e none or aes256. With -e aes256 the shared secret is stored encrypted, with none in plain text
aaaconfig --authspec "tacacs+;local" -nologoutUnchanged
aaaconfig --add … -conf ldap -p 389 (the abandoned attempt)Valid, and 8.2.x and 9.2.x add -tls_mode starttls or ldaps
userconfig --change root -e yes, rootaccess --set allFrom Fabric OS 9.1.1 there is no accessible root account. In versions that have one it is disabled by default and reachable over the serial console only

Today the choice would be -a chap and -e aes256. Whether Fabric OS 8.0.1 already had -e aes256 and -tls_mode could not be confirmed.

← solutionz