Cordex®CXCHPControllerSoftwareManual|20-Maintainingthecontroller
Notice: The user can pick any attribute supported by RADIUS to return the user role. The
important thing is that the attribute ID used must match the attribute used to define the user's role
in the RADIUS server's user configuration.
• Remote Authentication Type: WhensettoRADIUS (TACACS+ is disabled),usersareallowed
tobeauthenticatedbyaRADIUSserver.
• RADIUS Authentication Server Address: TheDNSnameortheIPv4/IPv6addressforthe
RADIUSserver.
• RADIUS Authentication Server Port: Thedefaultportis1812.
• RADIUS Timeout: Thetime,inseconds,thatthecontrollerwaitsforaresponsefromtheRADIUS
server.
• RADIUS Encryption Protocol: Theauthenticationmethodusedbythecontrollertoencrypt
userpasswords.ThisiseitherPasswordAuthenticationProtocol(PAP)orChallenge-Handshake
AuthenticationProtocol(CHAP).
• RADIUS Server Shared Secret: ThesharedsecretbetweenthecontrollerandtheRADIUS
server.SetthisvaluebyusingtheSet Shared Secret button.Youcancleartheconfiguredshared
secretbyusingtheClear Shared Secret button.
20.7.2. TACACS+ authentication
TerminalAccessControllerAccessControlSystemPlus(TACACS+)isaclient/serverprotocoland
softwarethatenablesclientstocommunicatewithacentralservertoauthenticateandauthorizetheir
accesstotherequestedsystemorservice.ThissectiondescribesTACACS+authenticationand
authorization,itsfeatures,andhowtosetupthecontrollerasaTACACS+client.
Notice: See your TACACS+ server documents for any detailed information on setting up the
TACACS+ server.
20.7.2.1. TACACS+ authentication
TheCordex®CXCHPcontrollercanbeconfiguredtouseaTACACS+servertoremotelyauthenticate
users.Inthiscase,thecontrollerisactingasaTACACS+client.ATACACS+server,suchas
TACACS.net,mustbeconfiguredseparatelyforremoteauthenticationtoworkcorrectly.
ThefollowingarefeaturesforusingTACACS+authentication.
• Encryption Protocol: ProvidesencryptedPasswordAuthenticationProtocol(PAP),Challenge-
HandshakeAuthenticationProtocol(CHAP),orASCIIAuthentication.
• Encrypted TACACS+ Secret Key: Providesasecurelyencrypted,secretkeywhichisnotsent
betweenthecontrollerandtheTACACS+server.Thesecretkeymustbesetidenticallyonboththe
controllerandtheTACACS+server.
Page 216 0350058-J0 Rev AL