Chapter 30: Tacacs+/Radius Proxy - Tavve zoneranger User Manual

Table of Contents

Advertisement

Chapter 30: TACACS+/RADIUS Proxy

A ZoneRanger and one or more joined Ranger Gateways can provide a TACACS+ and/or RADIUS
proxy service, allowing devices located in a firewall-partitioned network zone to make TACACS+
and/or RADIUS Authentication, Authorization and Accounting (a.k.a. AAA) requests to a ZoneRanger,
which forwards the requests to a Ranger Gateway, which in turn forwards the requests to a TACACS+
and/or RADIUS server. Replies from the server follow the reverse path through the Ranger Gateway,
the ZoneRanger, and back to the device that made the initial request.
The following figure provides a high-level overview of a TACACS+/RADIUS proxy transaction.
Figure 30-1. ZoneRanger TACACS+/RADIUS Proxy
The TACACS+/RADIUS proxy enables devices located in firewall-partitioned networks to use
TACACS+ and/or RADIUS services, without requiring the firewall to be configured to pass TACACS+
or RADIUS messages. You can also use the TACACS+/RADIUS proxy to control access to the
ZoneRanger itself.
Configuring TACACS+/RADIUS Proxy on a ZoneRanger
In order for the ZoneRanger to be able to proxy TACACS+ and/or RADIUS traffic, it must be
joined to one or more Ranger Gateways, and one or more server groups must be defined. A server
group is a named set of TACACS+/RADIUS server entries, each of which contains the following
information:
The joined Ranger Gateway to be used to relay traffic to a given TACACS+/RADIUS
server.
The host name or IP address of the TACACS+/RADIUS server.
The TACACS+ port on the given server.
The RADIUS authentication and accounting ports on the given server.
Server groups can be configured with multiple entries, in order to provide high availability. Multiple
server groups can be defined, allowing TACACS+/RADIUS traffic for different devices to be routed
to different groups of servers. Once a set of server groups has been defined, proxy rules must be
configured for each protocol, associating managed devices, or groups of managed devices, with the
server group that should be used for those devices. Each proxy rule associates an IP address, or
range of IP addresses, with a server group name. Separate proxy rule tables are provided for
TACACS+ and RADIUS. As an example, the simplest possible configuration would be as follows:
Define a single server group named " MyServerGroup "
Add the following proxy rule to the TACACS+ table:
*.*.*.* MyServerGroup
ZoneRanger 5.5 User's Guide
102

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents