TACACS+ Servers for AAA
This chapter describes how to configure TACACS+ servers used in AAA and includes the following sections:
Information About TACACS+ Servers
The ASA supports TACACS+ server authentication with the following protocols: ASCII, PAP, CHAP, and MS-CHAPv1.
Using TACACS+ Attributes
The ASA provides support for TACACS+ attributes. TACACS+ attributes separate the functions of authentication, authorization, and accounting. The protocol supports two types of attributes: mandatory and optional. Both the server and client must understand a mandatory attribute, and the mandatory attribute must be applied to the user. An optional attribute may or may not be understood or used.
Note To use TACACS+ attributes, make sure that you have enabled AAA services on the NAS.
Table 37-1 lists supported TACACS+ authorization response attributes for cut-through-proxy connections. Table 37-2 lists supported TACACS+ accounting attributes.
Licensing Requirements for TACACS+ Servers
|
|
---|---|
Guidelines and Limitations
This section includes the guidelines and limitations for this feature.
Supported in single and multiple context mode.
Supported in routed and transparent firewall mode.
- You can have up to 100 server groups in single mode or 4 server groups per context in multiple mode.
- Each group can have up to 16 servers in single mode or 4 servers in multiple mode.
- If you need to configure fallback support using the local database, see Fallback Support and the How Fallback Works with Multiple Servers in a Group.
- To prevent lockout from the ASA when using TACACS+ authentication or authorization, see Recovering from a Lockout.
Configuring TACACS+ Servers
This section includes the following topics:
- Task Flow for Configuring TACACS+ Servers
- Configuring TACACS+ Server Groups
- Adding a TACACS+ Server to a Group
Task Flow for Configuring TACACS+ Servers
Step 1 Add a TACACS+ server group. See Configuring TACACS+ Server Groups.
Step 2 For a server group, add a server to the group. See Adding a TACACS+ Server to a Group.
Configuring TACACS+ Server Groups
If you want to use a TACACS+ server for authentication, authorization, or accounting, you must first create at least one TACACS+ server group and add one or more servers to each group. You identify TACACS+ server groups by name.
Detailed Steps
Examples
The following example shows how to add one TACACS+ group with one primary and one backup server:
Adding a TACACS+ Server to a Group
To add a TACACS+ server to a group, perform the following steps:
Detailed Steps
Monitoring TACACS+ Servers
To monitor TACACS+ servers,enter one of the following commands:
Feature History for TACACS+ Servers
Table 37-3 lists each feature change and the platform release in which it was implemented.