TACACS+ Configuration Example
The following example configures a TACACS+ server and related operations.
device# configure terminal /* First three lines define three authentication servers, port, function, and key */ device(config)# tacacs-server host 10.2.3.4 auth-port 49 authentication-only default key abc device(config)# tacacs-server host 10.2.3.5 auth-port 49 authorization-only default key def device(config)# tacacs-server host 10.2.3.6 auth-port 49 accounting-only default key ghi device(config)# aaa authorization exec default tacacs+ /* Authenticate Telnet access using TACACS+ first. If that fails, use local username and password. If that fails, permit access with no authentication. */ device(config)# aaa authentication login default tacacs+ local none /* On successful login, enter CLI at the privileged-EXEC level. */ device(config)# aaa authentication login privilege-mode /* Use TACACS+ to check the user's privilege level for commands entered. */ device(config)# aaa authorization commands 0 default tacacs+ /* Do TACACS+ accounting for SSH/Telnet, for all commands, and for all system events. */ device(config)# aaa accounting exec default start-stop tacacs+ device(config)# aaa accounting commands 0 default start-stop tacacs+ device(config)# aaa accounting system default start-stop tacacs+