Configuring a TACACS+ Server

Complete the following steps to configure a TACACS+ server.

  1. From the main menu, select Security > AAA Servers.
  2. Click the AAA Servers tab.
    All the configured servers are listed in the main pane. You can perform the following actions:
    • Add a server: Continue to step 3 to add a new server.
    • Edit a server: Click the icon to display the Edit Switch AAA Server dialog box. Make the necessary changes and click Apply, then click Ok in the confirmation window, to apply the changes.
    • Delete a server: Click the icon to display the Delete Switch AAA Server dialog box. Click Apply to delete the server.
  3. In the AAA Servers tab, click the icon to display the Add Switch AAA Server dialog box.

    Adding a TACACS+ Server

  4. Click Tacacs+ for the AAA server type.
  5. Complete the following fields:
    • IP Address: Assign an IP address to the TACACS+ server. The IP address can be in the IPv4 format or IPv6 format.
    • Auth. Port: Enter the TACACS+ authentication port number. The recommended value is 1812.
    • Shared Secret: Specify the shared secret text string (TACACS+ key) used between the device and the TACACS+ server to authenticate user access.
    • Confirm Secret: Re-enter the shared secret text.
    • Purpose: Designate the TACACS+ server to handle a specific AAA operation selected from the list:
      • Default: Configures the TACACS+ server to be used for any AAA operation.
      • Authentication: Configures the TACACS+ server to be used only for authentication.
      • Authorization: Configures the TACACS+ server to be used only for authorization.
      • Accounting: Configures the TACACS+ server to be used only for accounting.
  6. Click Apply, then click Ok in the confirmation window, to add the TACACS+ server.