Field/setting
Description
Type of TACACS+
Select an authentication protocol.
authentication
•
•
•
•
•
•
•
•
Port
The default port is 49
To use non-standard port, type a new port number.
Enable Accounting?
Default is enabled.
Accounting allows you to log activity executed on the TACACS+ server.
Timeout
Default is 10 seconds.
Maximum amount of time to establish contact with the server before timing out.
Enter the timeout period in seconds.
Retries
Default is 3.
Enter the number of retries.
Shared secret,
The shared secret is necessary to protect communication with the server.
Confirm shared secret
1) Click Add Server or Test Connection to verify the settings.
2) To add more servers, repeat the same steps.
3) In the TACACS+ page, use the arrow buttons to arrange the servers in the order they should be
accessed, then click Save.
4) To begin using the configuration, make sure TACACS+ is enabled: Go to Device Settings > Security >
Authentication, and select TACACS+ as the Authentication Type.
ASCII
PAP (Password Authentication Protocol)
CHAP (Challenge Handshake Authentication Protocol)
MS-CHAP (Microsoft Challenge Handshake Authentication Protocol)
CHAP is generally considered more secure because the user name and password
are encrypted, while in PAP they are transmitted in the clear.
MS‑CHAP provides stronger security than the other options.
Note: All authentication methods are insecure. It is strongly recommended
to use TACACS+ only in a secure networking environment. A warning
displays for all methods.
205
Need help?
Do you have a question about the Server Technology PRO3X and is the answer not in the manual?