TACACS/TACACS+ Configuration Considerations

  • You must deploy at least one TACACS/TACACS+ server in your network.
  • RUCKUS devices support authentication using up to eight TACACS/TACACS+ servers. The device tries to use the servers in the order you add them to the device configuration.
  • You can select only one primary authentication method for each type of access to a device (CLI through Telnet, CLI Privileged EXEC and CONFIG levels). For example, you can select TACACS+ as the primary authentication method for Telnet CLI access, but you cannot also select RADIUS authentication as a primary method for the same type of access. However, you can configure backup authentication methods for each access type. Refer to Configuring Authentication-method Lists for TACACS and TACACS+ for more information.
  • You can configure the RUCKUS device to authenticate using a TACACS or TACACS+ server, but not both.