ZXR105900/5200SeriesUserManual(BasicCongurationVolume)
TACACS+Configuration
TACACS+Overview
TACACS+,TerminalAccessControllerAccessControlSystem,is
themostpopularAAAprotocolwhichisthesimpliednameofAu-
thorization,AuthenticationandAccounting.TACACS+supportsin-
dependentauthentication,authorizationandaccounting,allowing
differentTACACS+securityservertobeauthentication,authoriza-
tionandaccountingserverrespectively.
PPPuserandTelnetuserthatusethesystemserviceshouldbeau-
thenticated,authorizedandaccountedinZXROS.TACACS+proto-
colcansolvethisproblemeffectively.TACACS+moduleprovides
centralizedsecurityauthentication,authorizationandaccounting
forlogginguser .
TACACS+softwaremoduleinZXROSisclientsoftwareauthen-
ticatedbyTACACS+.Itimplementstheprotocolinteractionbe-
tweenNASandTACACS+securityservertocompleteTACACS+
AAAfunction.TACACS+clientalsoprovidestheoperationthat
TACACS+congurationneedstocongureTACACS+environment.
Atpresent,ZXR105900/5200supportsTACACS+authentication
toprovideauthenticationofT elnetusersaccessingtherouters.
ZXR105900/5200supportsmultipleTACACS+servergroups.
EachTACACS+grouppermitsthecongurationoffourauthen-
ticationserversandeachgroupcanbeconguredwithtwo
parameters:servertimeouttimeandretrytimes.Theadminis-
tratorcanconguredifferentTACACS+servergroupstoselecta
specicTACACS+server .
ConfiguringTACACS+
1.ToenableTACACS+protocolfunction,usethefollowingcom-
mand.
CommandFunction
ZXR10(config)#tacacsenableThisenablesTACACS+protocol
function.
2.TodisableTACACS+protocolfunction,usethefollowingcom-
mmand.
CommandFunction
ZXR10(config)#tacacsdisable[clear]ThisdisablesTACACS+protocol
function.
3.TocongureTACACS+servergroupmember ,usethefollowing
command.
124CondentialandProprietaryInformationofZTECORPORATION