Setting Up Tacacs+ Authentication - Juniper J2300 User Manual

J-series services router
Hide thumbs Also See for J2300:
Table of Contents

Advertisement

Table 56: Setting Up RADIUS Authentication
Task
Navigate to the System level in the
configuration hierarchy.
Add a new RADIUS server
Specify the shared secret (password)
of the RADIUS server. The secret is
stored as an encrypted value in the
configuration database.
Specify the source address to be
included in the RADIUS server requests
by the router. In most cases, you can
use the loopback address of the router.

Setting Up TACACS+ Authentication

To use TACACS+ authentication, you must configure at least one TACACS+ server.
The procedure provided in this section identifies the TACACS+ server, specifies
the secret (password) of the TACACS+ server, and sets the source address
of the Services Router's TACACS+ requests to the loopback address of the
router. This procedure uses the following sample values:
To specify a system authentication order, see "Configuring Authentication
Order" on page 185.
To configure a remote user template account, see "Creating a Remote
Template Account" on page 189.
To configure local user template accounts, see "Creating a Local Template
Account" on page 190.
J-Web Configuration Editor
In the configuration editor hierarchy,
select System.
1.
In the Radius server box, click Add
new entry.
2.
In the Address box, type the IP
address of the RADIUS server:
172.16.98.1
In the Secret box, type the shared secret
of the RADIUS server:
Radiussecret1
In the Source address box, type the
loopback address of the router:
10.0.0.1
The TACACS+ server's IP address is
The TACACS+ server's secret is
The loopback address of the router is
Managing Users and Files with a Configuration Editor
Managing Users and Operations
CLI Configuration Editor
From the top of the configuration
hierarchy enter
edit system
Set the IP address of the RADIUS server:
set radius-server address 172.16.98.1
Set the shared secret of the RADIUS
server:
set radius-server 172.16.98.1 secret
Radiussecret1
Set the router's loopback address as the
source address:
set radius-server 172.16.98.1
source-address 10.0.0.1
.
172.16.98.24
.
Tacacssecret1
.
10.0.0.1
183

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

J2350J2320J4300J6300J6350J4350

Table of Contents