TRENDnet TI-PG1284i User Manual page 158

12-port hardened industrial gigabit poe+ layer 2+ managed din-rail switch
Hide thumbs Also See for TI-PG1284i:
Table of Contents

Advertisement

TRENDnet User's Guide
Multiple connect mode will be support.
Syslog messages will be support.
Functional Description
The Tacacs+ implementation will provide the following services:
Authentication:
Complete control of authentication through login and password dialog, challenge and
response, messaging support etc.
Authorization:
Control over user capabilities for the duration of the user session, like setting auto
commands, enforcing restrictions on what configuration commands a user may execute,
session duration etc.
Accounting :
Collecting and sending information used for billing, auditing, and reporting to the
TACACS+ daemon.
Each of the above mentioned services can be configured and run independent of the
others. The TACACS+ implementation will provide authentication and confidentiality
between the router and the TACACS+ daemon. It runs on TCP port 49.
Appliction:
Remote network access is witnessing a major paradigm shift that from terminal access to
LAN access. Single users want to connect to the corporate network in the same way that
they connect at work i.e. as a LAN user. This places increased emphasis on network access
security. As a result of this network managers are concerned with 3 parameters:
authentication, authorization and accounting. This is where TACACS+ enters into the
picture. A typical deployment using TACACS+ could be as follow:
© Copyright 2016 TRENDnet. All Rights Reserved.
Notices
Tacacs+ service must be enabled before configuring the authentication,
authorization and accounting parameters, otherwise it will return error as Tacacs+
service is not enabled.
Not allowed to disable the Authentication login mode when both enabled login-
mode and login local.
Not allowed to disable the Authentication enable mode when both enabled enable-
mode and enable local.
Not allowed to enable the login-mode local when login-mode is in disable.
Not allowed to enable the enable-mode local when enable-mode is in disable.
For input CLI, user must supply full command or partial command with TAB
(command must be completed). The reason is only the command after user HIT the
ENTER is only send to TACACS+ server for authorization or accounting. So if this
command is partial then subsequently authorization or accounting fails.
TI-PG1284i
155

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents