Configuring Authentication-method Lists for TACACS and TACACS+
You can use TACACS/TACACS+ to authenticate Telnet or SSH access as well as access to the Privileged EXEC level and CONFIG levels of the CLI. When configuring TACACS/TACACS+ authentication, you create authentication-method lists specifically for the different types of access.
Within the authentication-method list, specify TACACS or TACACS+ as the primary authentication method, and specify up to six backup authentication methods as alternates. If TACACS or TACACS+ authentication fails due to an error, the device tries the backup authentication methods in the order they appear in the list.
There are two different authentication-method lists for TACACS or TACACS+ authentication.
- Telnet/SSH - Use the
aaa authentication login defaultcommand followed by appropriate methods to create an authentication-method list for Telnet or SSH CLI access. - CLI - Use the
aaa authentication enable defaultcommand followed by appropriate methods to create a separate authentication-method list for access to the Privileged EXEC and CONFIG levels of the CLI.
The following example creates an authentication-method list that specifies TACACS as the primary authentication method for securing Telnet/SSH access. If TACACS authentication fails due to an error with the server, authentication is performed using local user accounts instead. If local authentication fails, access is denied.
device# configure terminal device(config)# enable telnet authentication device(config)# aaa authentication login default tacacs local
The following example creates an authentication-method list that specifies TACACS as the primary authentication method for access to the Privileged EXEC level and CONFIG levels of the CLI. If TACACS authentication fails due to an error with the server, local authentication is used instead. If local authentication fails, no authentication is used, and the device automatically permits access.
device(config)# aaa authentication enable default tacacs local none
The first method parameter (tacacs in the two previous examples) specifies the primary authentication method. The remaining optional method parameters specify additional methods to try if an error occurs with the primary method. A method can be one of the values listed in the Method Parameter column in the following Authentication Method Values table.
Authentication Method Values
| Method Parameter | Description |
|---|---|
|
line |
Authenticate using the password you configured for Telnet access. The Telnet password is configured using the enable telnet password... command. Refer to Configuring Telnet Remote Access. |
|
enable |
Authenticate using the password you configured for the Super User privilege level. This password is configured using the enable super-user-password... command. Refer to Configuring Local User Accounts. |
|
local |
Authenticate using a local user name and password you configured on the device. Local user names and passwords are configured using the username... command. Refer to Configuring Local User Accounts . |
|
tacacs |
Authenticate using the database on a TACACS server. You also
must identify the server to the device using the |
|
tacacs+ |
Authenticate using the database on a TACACS+ server. You also
must identify the server to the device using the |
|
radius |
Authenticate using the database on a RADIUS server. You also
must identify the server to the device using the
|
|
none |
Do not use any authentication method. The device automatically permits access. |