ZXR105250SeriesCongurationGuide
5.37TACACS+Conguration
TACACS+Overview
TerminalAccessControllerAccess-ControlSystemPlus(TACACS+)isdevelopedfrom
TACACSandXTACACS.ItisthelatestversionofTACACS(notcompatiblewiththe
previoustwoversions).ItisapopularAAAprotocolatpresent.
TACACS+supportsseparateauthentication,authorization,andaccounting.Different
TACACS+serverscanactrespectivelyastheauthentication,authorization,and
accountingservers.
ConguringTACACS+
TheTACACS+congurationincludesthefollowingcommands:
CommandFunction
zte(cfg-nas)#tacacs-plusgroup<group-name>{enable|disable}Enablesordisablesaserver
group.
zte(cfg-nas)#tacacs-plusgroup<group-name>{add|delete}host
<A.B.C.D>[<49,1025-65535>|<4-180>|<string>]
Addsordeletesaserver
in/fromaTACACS+server
group.
zte(cfg-nas)#tacacs-plusloginauthendefaultgroup<group-name>SetsthedefaultTACACS+
loginauthenticationserver
group.
zte(cfg-nas)#tacacs-plusloginauthordefaultgroup<group-name>Setsthedefaultservergroup
authorizedforTACACS+
login.
zte(cfg-nas)#tacacs-plusadminauthendefaultgroup<group-name>Setsthedefaultservergroup
authenticatedforTACACS+
management.
zte(cfg-nas)#tacacs-plusaccountingcommandsdefaultgroup
<group-name>
Setsthedefaultserver
groupforTACACS+MML
accounting.
zte(cfg-nas)#tacacs-plusaccountingexecdefaultgroup
<group-name>
Setsthedefaultserver
groupforTACACS+user
accounting.
zte(cfg-nas)#tacacs-plusaccountingupdateperiod<1-2147483647>Setstherefreshperiodfor
TACACS+useraccounting.
zte(cfg-nas)#cleartacacs-plusloginauthendefaultClearsthedefaultTACACS+
loginauthenticationserver
group.
5-136
SJ-20131111172707-002|2013-11-27(R1.0)ZTEProprietaryandCondential