ip tacacs source-interface : can vlan1 be used?

Unanswered Question
Apr 16th, 2007
User Badges:

Hi All,

I have a distribution box with multiple SVIs. In order to hop from one box to another box, I have added an ACL for the vty lines. The ACL has

access-list 10 permit

access-list 10 deny any log

But I do not have loopback interface configured on all devices yet. I tried using "ip tacacs source-interface vlan1" and "ip ssh source-interface vlan1" and it did not work. Does it only work with loopbacks?

  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
walleyewiz Mon, 04/16/2007 - 08:16
User Badges:

yes, i have used it on many switches.

From a current 3750:

ip tacacs source-interface Vlan1

Richard Burts Mon, 04/16/2007 - 08:32
User Badges:
  • Super Silver, 17500 points or more
  • Hall of Fame,

    Founding Member

  • Cisco Designated VIP,

    2017 LAN, WAN


I agree with Brad that the source-interface command is not restricted to loopback interfaces. It will use whatever interface you specify (as long as that interface is available). I have used the source-interface command with a variety of interfaces and it works. If you tried it before and it did not work then there must be some other explanation of the problem (perhaps the server not configured to match the address that you specified, perhaps a key mismatch, perhaps something else).



John Lukes Fri, 12/09/2016 - 14:09
User Badges:

Check the configuration for "vlan1" and post it here.

Is the name "vlan1" or "Vlan1" 


This Discussion