Configuring TACACS+ can be a bit of a challenge if you have never done it before.
But once you understand the format of the config file its really pretty simple.
Here’s a sample tacacs+ config :
# Encryption key is the same key you configure in your router # ENCYPTION KEY: key = password # You will want to log access to a file. Set that file here # Remember to rotate the log, it will grow over time. # write accounting to: accounting file = accounting.log ######################################### ###############Users##################### ######################################### ### without "login = " need to authenticate through radius or local: user = tom { member = itnetwork } user = dick { member = itnetwork } user = harry { member = itnetwork } user = backup-user { member = show } # show profile for only doing backups ################################ ##########Groups################ ################################ group = itnetwork { # IT-Network Engineers login = file passwords.db service = exec { default attribute = permit priv-lvl = 15 } cmd = show { permit .* } cmd = enable { permit .* } ################################################# # The remainder edited for breavity
In the above sample config there are basically three sections. The top section of the config is
where you define the encryption key that allows your routers and switches to authenticate to
your tacacs+ server.
The next section is the users section. This is where you define the user names , which group they
are a member of, and where the password is kept. In this example we are using a file called
passwords.db that contains these passwords.
Finally is the group section. This is where you define the commands that can be executed by
this group. Users can belong to multiple groups. Commands can be permitted or denied which
allows for an amazing amount of control over what users and groups can do on your network devices.
While TAC+ runs on the server, enter this command on the server to see the entries that go into the
accounting file:
tail -f /var/log/tac.log
For more advanced features check out Cisco Secure ACS Server.
The entire tacacs+ package can be downloaded here. It contains the entire tac.cfg file
Comments
(There are currently no comments for this post.)