Configuring Tacacs; About Configuring Tacacs; Information About Tacacs; Tacacs+ Advantages - Cisco Nexus 5000 Series Configuration Manual

Nx-os security configuration guide
Hide thumbs Also See for Nexus 5000 Series:
Table of Contents

Advertisement

Configuring TACACS+

This chapter describes how to configure the Terminal Access Controller Access Control System Plus
(TACACS+) protocol on Cisco NX-OS devices.

About Configuring TACACS+

Information About TACACS+

The Terminal Access Controller Access Control System Plus (TACACS+) security protocol provides centralized
validation of users attempting to gain access to a Cisco Nexus 5000 Series switch. TACACS+ services are
maintained in a database on a TACACS+ daemon typically running on a UNIX or Windows NT workstation.
You must have access to and must configure a TACACS+ server before the configured TACACS+ features
on your Cisco Nexus 5000 Series switch are available.
TACACS+ provides for separate authentication, authorization, and accounting facilities. TACACS+ allows
for a single access control server (the TACACS+ daemon) to provide each service (authentication, authorization,
and accounting) independently. Each service is associated with its own database to take advantage of other
services available on that server or on the network, depending on the capabilities of the daemon.
The TACACS+ client/server protocol uses TCP (TCP port 49) for transport requirements. Cisco Nexus 5000
Series switches provide centralized authentication using the TACACS+ protocol.

TACACS+ Advantages

TACACS+ has the following advantages over RADIUS authentication:
• Provides independent AAA facilities. For example, the Cisco Nexus 5000 Series switch can authorize
• Uses the TCP transport protocol to send data between the AAA client and server, making reliable transfers
• Encrypts the entire protocol payload between the switch and the AAA server to ensure higher data
OL-20919-01
About Configuring TACACS+, page 41
access without authenticating.
with a connection-oriented protocol.
confidentiality. The RADIUS protocol only encrypts passwords.
C H A P T E R
Cisco Nexus 5000 Series NX-OS Security Configuration Guide
5
41

Advertisement

Table of Contents
loading

Table of Contents