skip to content

TACACS+

TACACS+ runs authentication, authorization and accounting as separate TCP exchanges, obfuscates the whole packet body, and approves each command. Choosing it over RADIUS is a stock design question.

on this pageshow

explore

questions

page 2 of 2

What does a TACACS+ authentication REPLY with status RESTART ask of the network device, and what if it cannot comply?

level: seniorimportance: nice to knowfreq 24%

basics

~20 s

RESTART says the authentication type the device chose is unacceptable, and the sequence may begin again from a fresh START — typically with a different authen_type. A device that does not implement RESTART must process it as FAIL.

open as a page

Why must a TACACS+ server's authorization policy not branch on the authen_method value in the REQUEST?

level: seniorimportance: nice to knowfreq 24%

basics

~20 s

Because authen_method is the network device's own unverified claim about how the user was authenticated. RFC 8907 states the information is not always subject to verification and MUST NOT be used in policy evaluation; the server has no way to confirm it.

open as a page

A TACACS+ authentication session reaches seq_no 255 — what must happen, and why can the number not wrap?

level: seniorimportance: nice to knowfreq 20%

basics

~20 s

The session must terminate and be restarted with a sequence number of 1. seq_no is a single octet and the specification forbids it from wrapping, because the number and its parity are the only things that place a packet in its session.

open as a page

showing 31–33 of 33