TACACS+ Configuration Example

The following example configures a TACACS+ server and related operations.

device# configure terminal
/* First three lines define three authentication servers, port, function, and key */
device(config)# tacacs-server host 10.2.3.4 auth-port 49 authentication-only default key abc
device(config)# tacacs-server host 10.2.3.5 auth-port 49 authorization-only default key def
device(config)# tacacs-server host 10.2.3.6 auth-port 49 accounting-only default key ghi


device(config)# aaa authorization exec default tacacs+

/* Authenticate Telnet access using TACACS+ first. If that fails,
use local username and password. If that fails, permit access with no authentication. */
device(config)# aaa authentication login default tacacs+ local none
/* On successful login, enter CLI at the privileged-EXEC level. */
device(config)# aaa authentication login privilege-mode
/* Use TACACS+ to check the user's privilege level for commands entered. */
device(config)# aaa authorization commands 0 default tacacs+

/* Do TACACS+ accounting for SSH/Telnet, for all commands, and for all system events. */
device(config)# aaa accounting exec default start-stop tacacs+
device(config)# aaa accounting commands 0 default start-stop tacacs+
device(config)# aaa accounting system default start-stop tacacs+