Juniper J-Series Administration Manual page 36

Juniper networks router administration guide
Hide thumbs Also See for J-Series:
Table of Contents

Advertisement

J-series
Services Router Administration Guide
To configure TACACS+ authentication:
1.
2.
3.
4.
Table 12: Setting Up TACACS+ Authentication
Task
Navigate to the System level in the
configuration hierarchy.
Add a new TACACS+ server
Specify the shared secret (password) of
the TACACS+ server. The secret is
stored as an encrypted value in the
configuration database.
Specify the source address to be
included in the TACACS+ server
requests by the router. In most cases,
you can use the loopback address of the
router.
14
Managing User Authentication with a Configuration Editor
Navigate to the top of the configuration hierarchy in either the J-Web or CLI
configuration editor.
Perform the configuration tasks described in Table 12 on page 14.
If you are finished configuring the network, commit the configuration.
To completely set up TACACS+ authentication, you must create user template
accounts and specify a system authentication order.
Go on to one of the following procedures:
To specify a system authentication order, see "Configuring Authentication
Order" on page 15.
To configure a remote user template account, see "Creating a Remote
Template Account" on page 19.
To configure local user template accounts, see "Creating a Local Template
Account" on page 20.
J-Web Configuration Editor
1.
In the J-Web interface, select
Configuration>View and Edit>Edit
Configuration.
2.
Next to System, click Configure or
Edit.
1.
In the Tacplus server box, click Add
new entry.
2.
In the Address box, type the IP
address of the TACACS+ server:
172.16.98.24
In the Secret box, type the shared secret of
the TACACS+ server:
Tacacssecret1
In the Source address box, type the
loopback address of the router:
10.0.0.1
CLI Configuration Editor
From the
[edit]
hierarchy level, enter
edit system
Set the IP address of the TACACS+
server:
set tacplus-server address
172.16.98.24
Set the shared secret of the TACACS+
server:
set tacplus-server 172.16.98.24 secret
Tacacssecret1
Set the router's loopback address as
the source address:
set tacplus-server 172.16.98.24
source-address 10.0.0.1

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents