Skip to content

Login Domain

Location in GUI: Admin » AAA » Authentication » AAA

Diagram
NameTypeConstraintMandatoryDefault Value
login_domainsList[login_domains]No

NameTypeConstraintMandatoryDefault Value
nameStringRegex: ^[a-zA-Z0-9_.:-]{1,64}$Yes
realmChoicelocal, tacacs, ldap, radiusYes
descriptionStringRegex: ^[a-zA-Z0-9\\!#$%()*,-./:;@ _{|}~?&+]{1,128}$No
auth_choiceChoiceCiscoAVPair, LdapGroupMapNoCiscoAVPair
ldap_group_mapStringRegex: ^[a-zA-Z0-9_.:-]{1,31}$No
tacacs_providersList[tacacs_providers]No
ldap_providersList[ldap_providers]No
radius_providersList[radius_providers]No

tacacs_providers (apic.fabric_policies.aaa.login_domains)

Section titled “tacacs_providers (apic.fabric_policies.aaa.login_domains)”
NameTypeConstraintMandatoryDefault Value
hostname_ipAnyString[Regex: ^[a-zA-Z0-9:][a-zA-Z0-9.:-]{0,254}$] or IPYes
priorityIntegermin: 0, max: 16No0

ldap_providers (apic.fabric_policies.aaa.login_domains)

Section titled “ldap_providers (apic.fabric_policies.aaa.login_domains)”
NameTypeConstraintMandatoryDefault Value
hostname_ipAnyString[Regex: ^[a-zA-Z0-9:][a-zA-Z0-9.:-]{0,254}$] or IPYes
priorityIntegermin: 0, max: 16No0

radius_providers (apic.fabric_policies.aaa.login_domains)

Section titled “radius_providers (apic.fabric_policies.aaa.login_domains)”
NameTypeConstraintMandatoryDefault Value
hostname_ipAnyString[Regex: ^[a-zA-Z0-9:][a-zA-Z0-9.:-]{0,254}$] or IPYes
priorityIntegermin: 0, max: 16No0

Example 1: In this example we configure a login_domain named yourDomainRadius which adds 2 radius providers with a clear priority to define the order of usage.

apic:
fabric_policies:
aaa:
login_domains:
- name: yourDomainRadius
realm: radius
description: login domain radius
radius_providers:
- hostname_ip: 10.10.10.1
priority: 1
- hostname_ip: 10.10.10.2
priority: 2

Example 2: In this example we configure a login_domain named yourDomainTacacs which adds 2 tacacs providers with a clear priority to define the order of usage.

apic:
fabric_policies:
aaa:
login_domains:
- name: yourDomainTacacs
realm: tacacs
description: login domain tacacs
tacacs_providers:
- hostname_ip: 11.11.11.1
priority: 1
- hostname_ip: 11.11.11.2
priority: 2

Example 3: In this example we configure the local login domain and add a description to it.

apic:
fabric_policies:
aaa:
login_domains:
- name: yourLocalDomain
description: Local Domain
realm: local

Location in GUI: Admin » AAA » Authentication » AAA

Diagram
NameTypeConstraintMandatoryDefault Value
login_domainsList[login_domains]No

NameTypeConstraintMandatoryDefault Value
nameStringRegex: ^[a-zA-Z0-9_.:-]{1,64}$Yes
realmChoicelocal, tacacs, ldap, radiusYes
descriptionStringRegex: ^[a-zA-Z0-9\\!#$%()*,-./:;@ _{|}~?&+]{1,128}$No
auth_choiceChoiceCiscoAVPair, LdapGroupMapNoCiscoAVPair
ldap_group_mapStringRegex: ^[a-zA-Z0-9_.:-]{1,31}$No
tacacs_providersList[tacacs_providers]No
ldap_providersList[ldap_providers]No
radius_providersList[radius_providers]No

tacacs_providers (apic.fabric_policies.aaa.login_domains)

Section titled “tacacs_providers (apic.fabric_policies.aaa.login_domains)”
NameTypeConstraintMandatoryDefault Value
hostname_ipAnyString[Regex: ^[a-zA-Z0-9:][a-zA-Z0-9.:-]{0,254}$] or IPYes
priorityIntegermin: 0, max: 16No0

ldap_providers (apic.fabric_policies.aaa.login_domains)

Section titled “ldap_providers (apic.fabric_policies.aaa.login_domains)”
NameTypeConstraintMandatoryDefault Value
hostname_ipAnyString[Regex: ^[a-zA-Z0-9:][a-zA-Z0-9.:-]{0,254}$] or IPYes
priorityIntegermin: 0, max: 16No0

radius_providers (apic.fabric_policies.aaa.login_domains)

Section titled “radius_providers (apic.fabric_policies.aaa.login_domains)”
NameTypeConstraintMandatoryDefault Value
hostname_ipAnyString[Regex: ^[a-zA-Z0-9:][a-zA-Z0-9.:-]{0,254}$] or IPYes
priorityIntegermin: 0, max: 16No0

apic:
fabric_policies:
aaa:
login_domains:
- name: tacacs
realm: tacacs
description: login domain tacacs
tacacs_providers:
- hostname_ip: 1.1.1.1
priority: 1
- name: radius
realm: radius
description: login domain radius
radius_providers:
- hostname_ip: 3.3.3.1
priority: 1
- name: ldap
realm: ldap
description: login domain ldap
auth_choice: LdapGroupMap
ldap_group_map: test-users-map
ldap_providers:
- hostname_ip: 2.2.2.2
priority: 1

Location in GUI: Admin » AAA » Authentication » AAA

Diagram
NameTypeConstraintMandatoryDefault Value
login_domainsList[login_domains]No

NameTypeConstraintMandatoryDefault Value
nameStringRegex: ^[a-zA-Z0-9_.:-]{1,64}$Yes
realmChoicelocal, tacacs, ldap, radiusYes
descriptionStringRegex: ^[a-zA-Z0-9\\!#$%()*,-./:;@ _{|}~?&+]{1,128}$No
auth_choiceChoiceCiscoAVPair, LdapGroupMapNoCiscoAVPair
ldap_group_mapStringRegex: ^[a-zA-Z0-9_.:-]{1,31}$No
tacacs_providersList[tacacs_providers]No
ldap_providersList[ldap_providers]No
radius_providersList[radius_providers]No

tacacs_providers (apic.fabric_policies.aaa.login_domains)

Section titled “tacacs_providers (apic.fabric_policies.aaa.login_domains)”
NameTypeConstraintMandatoryDefault Value
hostname_ipAnyString[Regex: ^[a-zA-Z0-9:][a-zA-Z0-9.:-]{0,254}$] or IPYes
priorityIntegermin: 0, max: 16No0

ldap_providers (apic.fabric_policies.aaa.login_domains)

Section titled “ldap_providers (apic.fabric_policies.aaa.login_domains)”
NameTypeConstraintMandatoryDefault Value
hostname_ipAnyString[Regex: ^[a-zA-Z0-9:][a-zA-Z0-9.:-]{0,254}$] or IPYes
priorityIntegermin: 0, max: 16No0

radius_providers (apic.fabric_policies.aaa.login_domains)

Section titled “radius_providers (apic.fabric_policies.aaa.login_domains)”
NameTypeConstraintMandatoryDefault Value
hostname_ipAnyString[Regex: ^[a-zA-Z0-9:][a-zA-Z0-9.:-]{0,254}$] or IPYes
priorityIntegermin: 0, max: 16No0

apic:
fabric_policies:
aaa:
login_domains:
- name: tacacs
realm: tacacs
description: login domain tacacs
tacacs_providers:
- hostname_ip: 1.1.1.1
priority: 1
- name: radius
realm: radius
description: login domain radius
radius_providers:
- hostname_ip: 3.3.3.1
priority: 1
- name: ldap
realm: ldap
description: login domain ldap
auth_choice: LdapGroupMap
ldap_group_map: test-users-map
ldap_providers:
- hostname_ip: 2.2.2.2
priority: 1

Location in GUI: Admin » AAA » Authentication » AAA

Diagram
NameTypeConstraintMandatoryDefault Value
login_domainsList[login_domains]No

NameTypeConstraintMandatoryDefault Value
nameStringRegex: ^[a-zA-Z0-9_.:-]{1,64}$Yes
realmChoicelocal, tacacs, ldap, radiusYes
descriptionStringRegex: ^[a-zA-Z0-9\\!#$%()*,-./:;@ _{|}~?&+]{1,128}$No
auth_choiceChoiceCiscoAVPair, LdapGroupMapNoCiscoAVPair
ldap_group_mapStringRegex: ^[a-zA-Z0-9_.:-]{1,31}$No
tacacs_providersList[tacacs_providers]No
ldap_providersList[ldap_providers]No
radius_providersList[radius_providers]No

tacacs_providers (apic.fabric_policies.aaa.login_domains)

Section titled “tacacs_providers (apic.fabric_policies.aaa.login_domains)”
NameTypeConstraintMandatoryDefault Value
hostname_ipAnyString[Regex: ^[a-zA-Z0-9:][a-zA-Z0-9.:-]{0,254}$] or IPYes
priorityIntegermin: 0, max: 16No0

ldap_providers (apic.fabric_policies.aaa.login_domains)

Section titled “ldap_providers (apic.fabric_policies.aaa.login_domains)”
NameTypeConstraintMandatoryDefault Value
hostname_ipAnyString[Regex: ^[a-zA-Z0-9:][a-zA-Z0-9.:-]{0,254}$] or IPYes
priorityIntegermin: 0, max: 16No0

radius_providers (apic.fabric_policies.aaa.login_domains)

Section titled “radius_providers (apic.fabric_policies.aaa.login_domains)”
NameTypeConstraintMandatoryDefault Value
hostname_ipAnyString[Regex: ^[a-zA-Z0-9:][a-zA-Z0-9.:-]{0,254}$] or IPYes
priorityIntegermin: 0, max: 16No0

apic:
fabric_policies:
aaa:
login_domains:
- name: tacacs
realm: tacacs
description: login domain tacacs
tacacs_providers:
- hostname_ip: 1.1.1.1
priority: 1
- name: radius
realm: radius
description: login domain radius
radius_providers:
- hostname_ip: 3.3.3.1
priority: 1
- name: ldap
realm: ldap
description: login domain ldap
auth_choice: LdapGroupMap
ldap_group_map: test-users-map
ldap_providers:
- hostname_ip: 2.2.2.2
priority: 1