Configuring Tacacs - Cisco 2100 Series Configuration Manual

Wireless lan controller
Hide thumbs Also See for 2100 Series:
Table of Contents

Advertisement

Configuring TACACS+

Table 5-6
Attribute ID
64
65
81
Table 5-7
Attribute ID
1
2
3
7
8
9-14
15
Configuring TACACS+
Terminal Access Controller Access Control System Plus (TACACS+) is a client/server protocol that
provides centralized security for users attempting to gain management access to a controller. It serves as
a backend database similar to local and RADIUS. However, local and RADIUS provide only
authentication support and limited authorization support while TACACS+ provides three services:
Cisco Wireless LAN Controller Configuration Guide
5-18
Accounting Attributes for Accounting Requests (continued)
Description
Tunnel-Type
Tunnel-Medium-Type
Tunnel-Group-ID
Accounting-Status-Type Attribute Values
Description
Start
Stop
Interim-Update
Accounting-On
Accounting-Off
Reserved for Tunneling Accounting
Reserved for Failed
Authentication—The process of verifying users when they attempt to log into the controller.
Users must enter a valid username and password in order for the controller to authenticate users to
the TACACS+ server. The authentication and authorization services are tied to one another. For
example, if authentication is performed using the local or RADIUS database, then authorization
would use the permissions associated with the user in the local or RADIUS database (which are
read-only, read-write, and lobby-admin) and not use TACACS+. Similarly, when authentication is
performed using TACACS+, authorization is tied to TACACS+.
Note
When multiple databases are configured, you can use the controller GUI or CLI to specify
the sequence in which the backend databases should be tried.
Authorization—The process of determining the actions that users are allowed to take on the
controller based on their level of access.
For TACACS+, authorization is based on privilege (or role) rather than specific actions. The
available roles correspond to the seven menu options on the controller GUI: MONITOR, WLAN,
CONTROLLER, WIRELESS, SECURITY, MANAGEMENT, and COMMANDS. An additional
role, LOBBY, is available for users who require only lobby ambassador privileges. The roles to
which users are assigned are configured on the TACACS+ server. Users can be authorized for one
or more roles. The minimum authorization is MONITOR only, and the maximum is ALL, which
authorizes the user to execute the functionality associated with all seven menu options. For example,
a user who is assigned the role of SECURITY can make changes to any items appearing on the
Chapter 5
Configuring Security Solutions
OL-17037-01

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

4400 series

Table of Contents