Specifications
Chapter 8 Authentication Services
PAP - Password Authentication Protocol
CHAP - Challenge Handshake Authentication Protocol (default)
MS-CHAP - Microsoft Challenge Handshake Authentication Protocol
b. In the Shared Secret field, type the shared secret (configured on the TACACS+ server in step 1), which is a
password protected field. (For the shared secret, Microsoft’s implementation allows up to 128 ASCII characters
and Cisco’s implementation allows up to 32 ASCII characters; other servers may have a different limit.)
NOTE: If you change the authentication type, you will be required to enter the shared secret.
c. Re-enter the shared secret in the Confirm Shared Secret field.
d. Click Next.
8. The Specify TACACS+ Group Authorization Method window will open.
a. Click the corresponding radio button to choose one of the following options to manage group authorization:
• DTX Control internal groups: Choose this option if you plan to associate TACACS+ users with DTX Control
internal user groups.
• TACACS+ privilege level attribute: Choose this option if you plan to associate TACACS+ users with
external TACACS+ groups using the privilege level attribute.
• TACACS+ custom attribute for group names: Choose this option if you plan to associate TACACS+ users
with external TACACS+ groups using the custom group names attribute.
b. Click Next.
9. If you selected DTX Control internal groups and the external authentication service was added successfully, the
Completed Successful window will open.
-or-
If you selected any other option, the Specify TACACS+ Server Group Authorization Settings window will open.
a. In the Service field, type the appropriate TACACS+ service.
If you selected the privilege level attribute method in step 8, the default value shell will appear in the field
by default.
If you selected the group name custom attribute method in step 8, the default value raccess will appear
in the field by default.
b. If the TACACS+ service requires a protocol for authorization requests, type the protocol in the Protocol field.
c. In the Attribute Name field, type the attribute name that the DTX Control server will receive after an authorization
request.
If you selected the privilege level attribute method in step 8, the default value priv-lvl will appear by
default.
If you selected the group name custom attribute method in step 8, the default value group_name will
appear by default.
10. Click Next. If the external authentication service is added successfully, the Completed Successful window will open.
11. Click Finish. The User Authentication Services window will open with the new service listed.
To change settings for the TACACS+ external authentication service:
1. Click the Users tab.
2. Click Authentication Services in the top navigation bar. The User Authentication Services window will open.
724-746-5500 | blackbox.com Page 70