Fortinet FortiGate Series Administration Manual page 277

Hide thumbs Also See for FortiGate Series:
Table of Contents

Advertisement

System Admin
Configuring TACACS+ authentication for administrators
FortiGate Version 4.0 MR1 Administration Guide
01-410-89802-20090903
http://docs.fortinet.com/
Feedback
5 Select OK.
Terminal Access Controller Access-Control System (TACACS+) is a remote
authentication protocol that provides access control for routers, network access servers,
and other networked computing devices via one or more centralized servers.
If you have configured TACACS+ support and an administrator is required to authenticate
using a TACACS+ server, the FortiGate unit contacts the TACACS+ server for
authentication. If the TACACS+ server cannot authenticate the administrator, the
connection is refused by the FortiGate unit.
If you want to use an TACACS+ server to authenticate administrators in your VDOM, you
must configure the authentication before you create the administrator accounts. To do this
you need to:
configure the TACACS+ server
configure the FortiGate unit to access the TACACS+ server
create a user group with the TACACS+ server as a member.
To view the TACACS+ server list, go to User > Remote > TACACS+.
Figure 125: Example TACACS+ server list
Create New
Server
Authentication Type
Delete icon
Edit icon
To configure the FortiGate unit to access the TACACS+ server
1 Go to User > Remote > TACACS+.
2 Select Create New, or select the Edit icon beside an existing TACACS+ server.
3 Enter the Name that identifies the TACACS+ server.
4 For Server Name/IP, enter the server domain name or IP address of the TACACS+
server.
5 For Server Key, enter the key to access the TACACS+ server. The maximum number
is 16.
6 For Authentication Type, enter one of Auto, ASCII, PAP, CHAP, and MSCHAP. Auto
authenticates using PAP, MSCHAP, and CHAP (in that order).
7 Select OK.
Add a new TACACS+ server.
The server domain name or IP address of the TACACS+ server.
The supported authentication method. TACACS+ authentication
methods include: Auto, ASCII, PAP, CHAP, and MSCHAP.
Delete this TACACS+ server
Edit this TACACS+ server.
Administrators
Delete
Edit
277

Advertisement

Table of Contents
loading

Table of Contents