TACACS+ server configuration

TACACS+ (Terminal Access Controller Access Control System) is an authentication protocol that allows a remote access server to forward a user's logon password to an authentication server to determine whether access can be allowed to a given system. TACACS+ and Remote Authentication Dial-In User Service (RADIUS) protocols are more secure than the TACACS encryption protocol. TACACS+ is described in RFC 1492.

TACACS+ protocol is more reliable than RADIUS, as TACACS+ uses the Transmission Control Protocol (TCP) whereas RADIUS uses the User Datagram Protocol (UDP). Also, RADIUS combines authentication and authorization in a user profile, whereas TACACS+ separates the two operations.

TACACS+ offers the following advantages over RADIUS as the authentication device:

TACACS+ is TCP-based, so it facilitates connection-oriented traffic.

It supports full-packet encryption, as opposed to password-only in authentication requests.

It supports decoupled authentication, authorization, and accounting.

The following table describes the TACACS+ Server Configuration commands.

Table 59 TACACS+ Server Configuration commands

Command

Description

[no] tacacs-server host <IP address>

Defines the primary TACACS+ server address.

 

Command mode: Global configuration

[no] tacacs-server host <IP address> key <1-32 characters>

Defines the primary or secondary shared secret between the switch and the TACACS+ server(s).

Command mode: Global configuration

tacacs-server port <TCP port number>

Enter the number of the TCP port to be configured, between 1 -

 

65000. The default is 49.

 

Command mode: Global configuration

tacacs-server retransmit <1-3>

Sets the number of failed authentication requests before

 

switching to a different TACACS+ server. The range is 1-3

 

requests. The default is 3 requests.

 

Command mode: Global configuration

tacacs-server timeout <4-15>

Sets the amount of time, in seconds, before a TACACS+ server

 

authentication attempt is considered to have failed. The range

 

is 4-15 seconds. The default is 5 seconds.

 

Command mode: Global configuration

[no] tacacs-server telnet-backdoor

Enables or disables the TACACS+ back door for telnet. The

 

telnet command also applies to SSH/SCP connections and

 

the Browser-based Interface (BBI). This command does not

 

apply when secure backdoor (secbd) is enabled.

 

Command mode: Global configuration

[no] tacacs-server secure-backdoor

Enables or disables the TACACS+ back door using secure

 

password for telnet/SSH/ HTTP/HTTPS. This command does

 

not apply when backdoor (telnet) is enabled.

 

Command mode: Global configuration

[no] tacacs-server privilege-mapping

Enables or disables TACACS+ privilege-level mapping.

 

The default value is disabled.

 

Command mode: Global configuration

tacacs-server user-mapping {<0-15> useroperadmin}

Maps a TACACS+ authorization level to this switch user level. Enter a TACACS+ privilege level (0-15), followed by the corresponding the user level (user, oper, admin).

Command mode: Global configuration

tacacs-server enable

Enables the TACACS+ server.

 

Command mode: Global configuration

no tacacs-server enable

Disables the TACACS+ server.

 

Command mode: Global configuration

show tacacs-server

Displays current TACACS+ configuration parameters.

 

Command mode: All

Configuration Commands 62

Page 62
Image 62
NEC N8406-022 manual TACACS+ server configuration

N8406-022 specifications

The NEC N8406-022 is a robust and versatile networking device designed primarily for organizations requiring high-performance connectivity solutions. As part of NEC's extensive portfolio of networking equipment, the N8406-022 is engineered to address the demands of modern enterprise environments, ensuring seamless communication and data processing capabilities.

One of the key features of the N8406-022 is its multi-layer switching functionality. This device supports Layer 2 and Layer 3 switching, allowing for efficient data routing and reducing latency within local area networks (LANs). This capability is particularly beneficial for businesses that rely on real-time data access and transfer, such as those in financial services, media, and telecommunications.

The N8406-022 is equipped with advanced Quality of Service (QoS) features that help prioritize critical network traffic. This means that voice and video data packets can be given precedence over less time-sensitive information, ensuring that essential communication remains clear and uninterrupted. This is crucial for organizations leveraging VoIP and video conferencing solutions.

In terms of connectivity, the NEC N8406-022 offers a variety of ports, including multiple Gigabit Ethernet ports, which facilitate high-speed data transfer and enable seamless integration into existing network infrastructures. The device may also include 10 Gigabit SFP+ ports, providing the flexibility for high-capacity uplinks to support bandwidth-intensive applications and storage solutions.

Security is another focal point of the NEC N8406-022, with integrated features such as VLAN support, access control lists (ACLs), and port security measures. These capabilities protect sensitive data from unauthorized access and ensure that only legitimate users and devices can connect to the network.

Moreover, the N8406-022 often incorporates advanced energy-efficient technologies that minimize power consumption without compromising performance. This not only contributes to operational cost savings but also supports organizations in their sustainability efforts.

With its combination of performance, security, and energy efficiency, the NEC N8406-022 stands out as a reliable networking solution suitable for a wide range of enterprises looking to enhance their connectivity and operational efficiency. Whether deployed in data centers or as part of a corporate network, this device is built to meet the evolving demands of today’s digital landscape.