Configuring Tacacs+; About Tacacs+; Advantages Of Tacacs+ - Cisco DS-C9216I-K9 Configuration Manual

Switch guide
Table of Contents

Advertisement

Chapter 18
Configuring Switch Security

Configuring TACACS+

A Cisco MDS switch uses the Terminal Access Controller Access Control System plus (TACACS+)
protocol to communicate with remote AAA servers. You can configure multiple TACACS+ servers and
set timeout values.
This section contains the following topics:

About TACACS+

TACACS+ is a client-server protocol which uses TCP (TCP port 49) for transport requirements. All
switches in the Cisco MDS 9000 Family provide centralized authentication using the TACACS+
protocol. The addition of TACACS+ support in SAN-OS 1.3(x) enables the following advantages over
RADIUS authentication:

Advantages of TACACS+

This section provides a brief list of advantages that TACACS+ has over and RADIUS.
OL-7753-01
accountinginfo—This attribute stores additional accounting information besides the attributes
covered by a standard RADIUS accounting protocol. This attribute is only sent in the VSA portion
of the Account-Request frames from the RADIUS client on the switch, and it can only be used with
the accounting protocol value.
About TACACS+, page 18-7
Advantages of TACACS+, page 18-7
Enabling TACACS+, page 18-8
Setting the TACACS+ Server Address, page 18-8
Setting the Secret Key, page 18-8
Setting the Timeout Value, page 18-8
Defining Custom Attributes for Roles, page 18-8
Provides independent, modular AAA facilities--authorization can be done without authentication.
Performs independent of servers if it is configured to its own database.
TCP transport protocol to send data between the AAA client and server, using reliable transfers with
a connection-oriented protocol
Encrypts the entire protocol payload between the switch and the AAA server to ensure higher data
confidentiality--the RADIUS protocol only encrypts passwords.
Uses TCP protocol which has a connection-oriented transport
Provides built-in transport support
Provides a separate acknowledgment that a request has been received
Provides immediate indication of a crashed, or not running, server
Detects server crashes out-of-band with actual requests
Cisco MDS 9000 Fabric Manager Switch Configuration Guide
Configuring TACACS+
18-7

Advertisement

Table of Contents
loading

Table of Contents