Comparing TACACS Authentication to TACACS+ Authentication

The following table describes the steps involved in TACACS authentication as compared to TACACS+ authentication.

TACACS Authentication TACACS+ Authentication

When TACACS authentication takes place, the following events occur.

  1. A user attempts to gain access to the RUCKUS device by doing one of the following:
    • Logging into the device using Telnet, SSH, or the Web Management Interface
    • Entering the Privileged EXEC level or CONFIG level of the CLI
  2. The user is prompted for a username and password.
  3. The user enters a username and password.
  4. The RUCKUS device sends a request containing the username and password to the TACACS server.
  5. The username and password are validated in the TACACS server database.
  6. If the password is valid, the user is authenticated.

When TACACS+ authentication takes place, the following events occur.

Note: Multiple challenges are supported for TACACS+ login authentication.

  1. A user attempts to gain access to the RUCKUS device by doing one of the following:
    • Logging into the device using Telnet, SSH, or the Web Management Interface
    • Entering the Privileged EXEC level or CONFIG level of the CLI
  2. The user is prompted for a username.
  3. The user enters a username.
  4. The RUCKUS device obtains a password prompt from a TACACS+ server.
  5. The user is prompted for a password.
  6. The user enters a password.
  7. The RUCKUS device sends the password to the TACACS+ server.
  8. The password is validated in the TACACS+ server database.
  9. If the password is valid, the user is authenticated.