XGS-5240-Series User Manual

Table Of Contents
Configuration Guide of XGS-5240-Series
51-1
Chapter 51 TACACS+ Configuration
51.1 Introduction to TACACS+
TACACS+ terminal access controller access control protocol is a protocol similar to
the radius protocol for control the terminal access to the network. Three independent f
unctions of Authentication, Authorization, Accounting are also available in this protocol.
Compared with RADIUS, the transmission layer of TACACS+ protocol is adopted with T
CP protocol, further with the packet head ( except for standard packet head) encryption,
this protocol is of a more reliable transmission and encryption characteristics, and is m
ore adapted to security control.
According to the characteristics of the TACACS+ (Version 1.78), we provide TACAC
S+ authentication function on the switch, when the user logs, such as telnet, the authe
ntication of user name and password can be carried out with TACACS+.
51.2 TACACS+ Configuration Task List
1. Configure the TACACS+ authentication key
2. Configure the TACACS+ server
3. Configure the TACACS+ authentication timeout time
4. Configure the IP address of the RADIUS NAS
1. Configure the TACACS+ authentication key
Command
Explanation
Global Mode
tacacs-server key {0 | 7}<string>
no tacacs-server key
Configure the TACACS+ server key; the
no tacacs-server key” command delet
es the key.
2. Configure TACACS+ server
Command
Explanation
Global Mode