User Guide

Managing Device Security
183
GS716Tv3, GS724Tv4, and GS748Tv5 Smart Switches
Configure TACACS+
TACACS+ provides a centralized user management system, while still retaining consistency
with RADIUS and other authentication processes. TACACS+ provides the following services:
Authentication. Provides authentication during login and through user names and
user-defined passwords.
Authorization. Performed at login. When the authentication session is completed, an
authorization session starts using the authenticated user name. The TACACS+ server
checks the user privileges.
The TACACS+ protocol ensures network security through encrypted protocol exchanges
between the device and TACACS+ server.
The TACACS+ folder contains links to the features described in the following sections.
Configure TACACS+
TACACS+ Server Configuration
TACACS+ Configuration
The TACACS+ Configuration screen contains the TACACS+ settings for communication
between the switch and the TACACS+ server you configure by using the inband
management port.
To configure global TACACS+ settings:
1. Select Security > Management Security > TACACS+ > TACACS+ Configuration.
2. In the Key String field, specify the authentication and encryption key for TACACS+
communications between the switch and the TACACS+ server.
The valid range is 0–128 characters. The key must match the key configured on the
TACACS+ server.
3. In the Connection Timeout field, specify the maximum number of seconds allowed to
establish a TCP connection between the switch and the TACACS+ server.
The valid range is 1–30 seconds. Default is 5 seconds.
4. Click the Apply button.