Thursday, December 18, 2008

Sample TACACS configuration for cisco router

In the router, you need to configure aaa authentication to enable the router querying the TACACS server for authentication data. As you might know, AAA stands for Authentication, Authorization, and Accounting. You should be able to do Authentication (Who are allowed to login), Authorization (What can he/she do when he/she logged in) and Accounting (What has he/she done during his login session).

Here is the sample configuration in the cisco router:
This configuration means, user's login session will authenticated first by Tacacs. If Tacacs failed, it will be authenticated agains the local user account. Remember username password command that you used during configuring PPP authentication.

After that you need to specify the tacacs servers:
In the Linux server where the TACACS service is running, you need to look for the tacacs configuration file. Normally it is located in /etc/tac_plus (for tacacs+)

Sample configuration;

No comments: