Configuring Authentication-method Lists for TACACS+
You can use TACACS+ to authenticate Telnet or SSH access as well as access to the Privileged EXEC level and CONFIG levels of the CLI. When configuring TACACS+ authentication, you create authentication-method lists specifically for the different types of access.
aaa authorization exec
default
tacacs+ command must be configured before the aaa authentication
login
default
tacacs+ command or the aaa authentication
enable
default
tacacs+ command can be configured. If you attempt to configure
either of these commands first, the following message is displayed: Warning- Please configure exec
authorization using TACACS+ to get user privilege.Within the authentication-method list, specify TACACS+ as the primary authentication method, and specify up to two backup authentication methods as alternates. If TACACS+ authentication fails due to an error, the device tries the backup authentication methods in the order they appear in the list.
There are two different authentication-method lists for TACACS+ authentication.
- Telnet/SSH - Use the
aaa authentication login defaultcommand followed by appropriate methods to create an authentication-method list for Telnet or SSH CLI access. - CLI - Use the
aaa authentication enable defaultcommand followed by appropriate methods to create a separate authentication-method list for access to the Privileged EXEC and CONFIG levels of the CLI.
The following example creates an authentication-method list that specifies TACACS+ as the primary authentication method for access to the Privileged EXEC level and CONFIG levels of the CLI. If TACACS+ authentication fails due to an error with the server, local authentication is used instead. If local authentication fails, no authentication is used, and the device automatically permits access.
device(config)# aaa authentication enable default tacacs+ local
The first method parameter (tacacs+ in the previous example) specifies the primary authentication method. The remaining optional method parameters specify additional methods to try if an error occurs with the primary method. A method can be one of the values listed in the Method Parameter column in the following Authentication Method Values table.
Authentication Method Values
| Method Parameter | Description |
|---|---|
|
local |
Authenticate using a local user name and password you configured on the device. Local user names and passwords are configured using the username... command. Refer to Configuring Local User Accounts . |
|
tacacs+ |
Authenticate using the database on a TACACS+ server. You also
must identify the server to the device using the |
|
radius |
Authenticate using the database on a RADIUS server. You also
must identify the server to the device using the
|