Configuring Authentication-method Lists for TACACS+

You can use TACACS+ to authenticate Telnet or SSH access as well as access to the Privileged EXEC level and CONFIG levels of the CLI. When configuring TACACS+ authentication, you create authentication-method lists specifically for the different types of access.

Note: The aaa authorization exec default tacacs+ command must be configured before the aaa authentication login default tacacs+ command or the aaa authentication enable default tacacs+ command can be configured. If you attempt to configure either of these commands first, the following message is displayed: Warning- Please configure exec authorization using TACACS+ to get user privilege.

Within the authentication-method list, specify TACACS+ as the primary authentication method, and specify up to two backup authentication methods as alternates. If TACACS+ authentication fails due to an error, the device tries the backup authentication methods in the order they appear in the list.

There are two different authentication-method lists for TACACS+ authentication.

  • Telnet/SSH - Use the aaa authentication login default command followed by appropriate methods to create an authentication-method list for Telnet or SSH CLI access.
  • CLI - Use the aaa authentication enable default command followed by appropriate methods to create a separate authentication-method list for access to the Privileged EXEC and CONFIG levels of the CLI.

The following example creates an authentication-method list that specifies TACACS+ as the primary authentication method for access to the Privileged EXEC level and CONFIG levels of the CLI. If TACACS+ authentication fails due to an error with the server, local authentication is used instead. If local authentication fails, no authentication is used, and the device automatically permits access.

device(config)# aaa authentication enable default tacacs+ local

The first method parameter (tacacs+ in the previous example) specifies the primary authentication method. The remaining optional method parameters specify additional methods to try if an error occurs with the primary method. A method can be one of the values listed in the Method Parameter column in the following Authentication Method Values table.

Authentication Method Values

Method Parameter Description

local

Authenticate using a local user name and password you configured on the device. Local user names and passwords are configured using the username... command.

Refer to Configuring Local User Accounts .

tacacs+

Authenticate using the database on a TACACS+ server. You also must identify the server to the device using the tacacs-server command.

radius

Authenticate using the database on a RADIUS server. You also must identify the server to the device using the radius-server command.