Specifying Different Servers for Individual AAA Functions

Separate TACACS+ servers can be configured and assigned for specific AAA tasks. For example, you can designate one TACACS+ server to handle authorization and another TACACS+ server to handle accounting. You can set the TACACS+ key for each server.

By default, the TACACS+ server performs all AAA functions. After authentication takes place, the server that performed authentication is used for authorization and accounting. If the authenticating server cannot perform the requested function, the next server in the configured list of servers is tried. This process repeats until a server that can perform the requested function is found or until every server in the configured list has been tried.

To specify different TACACS+ servers for authentication, authorization, and accounting, use the authentication-only, authorization-only, or accounting-only parameters as shown in the following example. The example also specifies a different TACACS+ key for each server as well as a port to be used for authentication (AAA operations).

device(config)# tacacs-server host 10.2.3.4 auth-port 49 authentication-only key abc
device(config)# tacacs-server host 10.2.3.5 auth-port 49 authorization-only key def
device(config)# tacacs-server host 10.2.3.6 auth-port 49 accounting-only key ghi

For TACACS+, the auth-port parameter specifies the TCP port number for the authentication port on the server. The default port number is 49.

For more information on the tacacs-server host command, refer to the RUCKUS FastIron Command Reference.