TACACS+
TACACS+ runs authentication, authorization and accounting as separate TCP exchanges, obfuscates the whole packet body, and approves each command. Choosing it over RADIUS is a stock design question.
on this pageshowhide
explore
- Wire Format and Sessions5 questions
- Authentication Exchange5 questions
- Per-Command Authorization6 questions
- Accounting and Auditing5 questions
- Payload Protection5 questions
- Comparison with RADIUS4 questions
- Deployment and Device Configuration3 questions
questions
page 2 of 2What does a TACACS+ authentication REPLY with status RESTART ask of the network device, and what if it cannot comply?
basics
~20 sRESTART says the authentication type the device chose is unacceptable, and the sequence may begin again from a fresh START — typically with a different authen_type. A device that does not implement RESTART must process it as FAIL.
Why must a TACACS+ server's authorization policy not branch on the authen_method value in the REQUEST?
basics
~20 sBecause authen_method is the network device's own unverified claim about how the user was authenticated. RFC 8907 states the information is not always subject to verification and MUST NOT be used in policy evaluation; the server has no way to confirm it.
A TACACS+ authentication session reaches seq_no 255 — what must happen, and why can the number not wrap?
basics
~20 sThe session must terminate and be restarted with a sequence number of 1. seq_no is a single octet and the specification forbids it from wrapping, because the number and its parity are the only things that place a packet in its session.
showing 31–33 of 33