Add a TACACS+ Server

Add a TACACS+ server, configure the TACACS+ server, and specify the authentication process.

If you have a secondary server configured, the AAA request goes to the backup server if the primary server is not available.

Before you begin

You must have access to and you must configure a TACACS+ server before the TACACS+ features on your switch are available.

About this task

The TACACS+ server and the switch must have the same:
  • Encryption key

  • Connection mode (single connection or per-session connection. Per-session is the same as multi-connection mode.)

  • TCP port number

Procedure

  1. In the navigation pane, expand Configuration > Security > Control Path.
  2. Select TACACS+.
  3. Select the TACACS+ Servers tab.
  4. Select Insert.
  5. In AddressType, select ipv4.
  6. In Address, type the IP address of the TACACS+ server.
  7. Optional: In PortNumber, type the TCP port on which the client establishes a connection to the TACACS+ server.
  8. Optional: In ConnectionType, select either singleConnection or perSessionConnection to specify the TCP connection type between the switch and TACACS+ server.
  9. Optional: In Timeout, type the period of time (in seconds) the switch waits for a response from the TACACS+ server.
  10. In Key, enter the key that the switch and the TACACS+ server share.
  11. In Priority, select either primary or backup to determine the order the switch uses the TACACS+ servers.
  12. Select Insert.

TACACS+ Servers Field Descriptions

Use the data in the following table to use the TACACS+ Servers tab.

Name

Description

AddressType

Specifies the type of IP address to use on the TACACS+ server. You must set the value to IPv4.

Address

Specifies the IP address of the TACACS+ server.

PortNumber

Configures the TCP port on which the client establishes a connection to the server. The default is 49. A value of 0 indicates that the system specified default value is used.

You must configure the same TCP port for the TACACS+ server and the switch.

ConnectionType

Specifies if the TCP connection between the device and the TACACS+ server is a single connection. If you specify the single connection parameter, the connection between the switch and the TACACS+ daemon remains open, which is more efficient because it allows the daemon to handle a higher number of TACACS+ operations. The single-connection session is torn down if TACACS+ is disabled due to inactivity.

If you do not configure this parameter, the switch uses the default connection type, which is the multi-connection. With the multi-connection, the connection opens and closes each time the switch and TACACS+ daemon communicate.

Note:

You must configure the same connection mode for the TACACS+ server and the switch.

To enable single-connection, the TACACS+ daemon has to support this mode as well.

ConnectionStatus

Specifies if the TCP connection between the device and TACACS+ server is connected or not connected.

Timeout

Configures the maximum time, in seconds, to wait for this TACACS+ server to reply before it times out. The default value is 10 seconds.

Key

Configures the authentication and encryption key for all TACACS+ communications between the device and the TACACS+ server. If the key length is zero, that indicates no encryption is used.

You must configure the same encryption key for the TACACS+ server and the switch.

Priority

Determines the order in which the switch uses the TACACS+ servers, where 1 is the highest priority. The priority values are primary and backup.

If more than one server shares the same priority, the device uses the servers in the order they exist in the table.