TACACS (Terminal Access Controller Access - Control System+) is a protocol created by CISCO Systems which provides access control to network devices (routers, network access servers and other networked computing devices) using one or more centralized servers. TACACS provides separate authentication, authorization, and accounting services running on different servers.
TACACS controls user access to devices and network resources while providing separate accounting, authentication, and authorization services. Some of the services provided by TACACS are:
To define a unique AAA TACACS configuration:
AAA TACACS Policy | Displays the name assigned to the AAA TACACS policy when it was initially created. The name cannot be edited within a listed profile. |
Accounting Access Method | Displays the connection method used to access the AAA TACACS accounting server. Options include All, SSH, Console, or Telnet. |
Authentication Access Method | Displays the method used to access the AAA TACACS authentication server. Options include All, SSH, Console, Telnet, or Web. |
Authorization Access Method | Displays the method used to access the AAA TACACS authorization server. Options include All, SSH, Console, or Telnet. |
Server Id | Set numerical server index (1-2) for the authentication server when added to the list of available TACACS authentication server resources. |
Host | Specify the IP address or hostname of the AAA TACACS server. |
Port | Define or edit the port on which the AAA TACACS server listens to traffic. The port range is 1 - 65,535. The default port is 49. |
Secret | Specify (and confirm) the secret (password) used for authentication between the selected AAA TACACS server and the controller, service platform or access point. By default the secret is displayed as asterisks. To see the secret being entered, select the Show option. |
Request Attempts | Set the number of connection request attempts to the TACACS server before it times out of the authentication session. The available range is from 1 - 10. The default is 3. |
Request Timeout | Specify the time for the re-transmission of request packets after an unsuccessful attempt. The default is 3 seconds. If the set time is exceeded, the authentication session is terminated. |
Retry Timeout Factor | Set the scaling of retransmission attempts from 50 - 200 seconds. The timeout at each attempt is the function of the retry timeout factor and the attempt number. 100 (the default value) implies a constant timeout on each retry. Smaller values indicate more aggressive (shorter) timeouts. Larger numbers define more conservative (larger) timeouts on each successive attempt. The default is 100. |
Server Id | Lists the numerical server index (1-2) for each authentication server when added to the list available to the controller, service platform or access point. |
Host | Displays the IP address or hostname set for the AAA TACACS authentication server. |
Port | Displays the port the TACACS authentication server listens to traffic. The port range is 1 - 65,535. The default port is 49. |
Secret | Specify (and confirm) the secret (password) used for authentication between the selected AAA TACACS server and the controller, service platform or access point. By default the secret is displayed as asterisks. To see the secret being entered, select the Show option. |
Request Attempts | Displays the number of connection attempts before the controller, service platform or access point times out of the authentication session. The available range is from 1 - 10. The default is 3. |
Request Timeout | Specify the time for the re-transmission of request packets after an unsuccessful attempt. The default is 3 seconds. If the set time is exceeded, the authentication session is terminated. |
Retry Timeout Factor | Set the scaling of retransmission attempts from 50 - 200 seconds. The timeout at each attempt is the function of the retry timeout factor and the attempt number. 100 (the default value) implies a constant timeout on each retry. Smaller values indicate more aggressive (shorter) timeouts. Larger numbers define more conservative (larger) timeouts on each successive attempt. The default is 100. |
Server Id | Lists the numerical server index (1-2) for each authentication server when added to the list available to the controller, service platform or Access Point. |
Host | Displays the IP address or hostname set for the AAA TACACS authentication server. |
Port | Displays the port the TACACS authentication server listens to traffic. The port range is 1 - 65,535. The default port |
Secret | Specify (and confirm) the secret (password) used for authentication between the selected AAA TACACS server and the controller, service platform or Access Point. By default the secret is displayed as asterisks. To show the secret in plain text, select |
Request Attempts | Displays the number of connection attempts before the controller, service platform or Access Point times out of the authentication session. The available range is from 1 - 10. The |
Request Timeout | Specify the time for the re-transmission of request packets after an unsuccessful attempt. The default is 3 seconds. If the set time is exceeded, the authentication session is terminated |
Retry Timeout Factor | Set the scaling of retransmission attempts from 50 - 200 seconds. The timeout at each attempt is the function of the retry timeout factor and the attempt number. 100 (the default value) implies a constant timeout on each retry. Smaller values indicate more aggressive (shorter) timeouts. Larger numbers define more conservative (larger) timeouts on each successive attempt. The default is 100 |
Authentication Access Method | Specify the connection method(s) for authentication
requests.
|
Directed Request | Select to enable the AAA TACACS authentication server to be used with the ‘@<server name>‘ nomenclature. The specified server must be present in the list of defined Authentication servers. |
Authorization Access Method | Specify the connection method(s) for authorization
requests.
|
Allow Privileged Commands | Select this option to enable privileged commands executed without command authorization. Privileged commands are commands that can alter/ change the authorization server configuration. |
Accounting Access Method | Specify the connection method(s) for accounting requests.
|
Authentication Failure | Select the option to enable accounting upon authentication failures. This setting is disabled by default. |
CLI Commands | Select this option to enable accounting for CLI commands. This setting is disabled by default. |
Session | Select this option to enable accounting for session start and session stop events. This setting is disabled by default. |
Service Name | Provide a 30 character maximum shell service for user authorization. |
Service Protocol | Enter a protocol for user authentication using the service. |
Note
A maximum or 5 entries can be made in the Service Protocol Settings table.