TACACS/TACACS+ Authentication, Authorization, and Accounting

When you configure a RUCKUS device to use a TACACS/TACACS+ server for authentication, the device prompts users who are trying to access the CLI for a user name and password and then verifies the password with the TACACS/TACACS+ server.

If you are using TACACS+, RUCKUS recommends that you also configure authorization, in which the RUCKUS device consults a TACACS+ server to determine which management privilege level (and which associated set of commands) an authenticated user is allowed to use. As an option, you can also configure accounting, which causes the RUCKUS device to log information on the TACACS+ server when specified events occur on the device.

Note: By default, a user logging into the device from Telnet or SSH first enters the User EXEC level and can then enter the enable command to access the Privileged EXEC level. A user who is successfully authenticated can be automatically placed at the Privileged EXEC level after login. Refer to Entering Privileged EXEC Mode after a Telnet or SSH Login.