Networking-Blog

My WordPress Blog

Centralizing Logins with TACACS+

Configuring TACACS+ can be a bit of a challenge if you have never done it before.
But once you understand the format of the config file its really pretty simple
.

Here’s a sample tacacs+ config :

# Encryption key is the same key you configure in your router
# ENCYPTION KEY:
	key = password

# You will want to log access to a file. Set that file here
# Remember to rotate the log, it will grow over time.
# write accounting to:
	accounting file = accounting.log

#########################################
###############Users#####################
#########################################

### without "login = " need to authenticate through radius or local:

	user 	= tom 		{ member = itnetwork }
	user 	= dick		{ member = itnetwork }
	user 	= harry		{ member = itnetwork }

	user	= backup-user	{ member = show } # show profile for only doing backups

################################
##########Groups################
################################

group = itnetwork {
		# IT-Network Engineers
        login = file passwords.db

		service	= exec {
			default attribute = permit
			priv-lvl = 15
		}

cmd = show {
                permit .*
                }
cmd = enable {
                permit .*
                }
#################################################
# The remainder edited for breavity

In the above sample config there are basically three sections.  The top section of the config is
where you define the encryption key that allows your routers and switches to authenticate to
your tacacs+ server.

The next section is the users section.  This is where you define the user names , which group they
are a member of, and where the password is kept.  In this example we are using a file called
passwords.db that contains these passwords.

Finally is the group section.  This is where you define the commands that can be executed by
this group. Users can belong to multiple groups.  Commands can be permitted or denied which
allows for an amazing amount of control over what users and groups can do on your network devices.

While TAC+ runs on the server, enter this command on the server to see the entries that go into the
accounting file:

tail -f /var/log/tac.log

For more advanced features check out Cisco Secure ACS Server.

The entire tacacs+ package can be downloaded here. It contains the entire tac.cfg file

Assign Privilege Levels with TACACS+ and RADIUS

AAA authorization limits the services available to a user.
When AAA authorization is enabled,  Devices uses information retrieved from the user profile, which is located either in the local user database or on the security server, to configure the user session.

The user is granted access to a requested service only if the information in the user profile allows it. You can use the aaa authorization command in global configuration mode with the tacacs+ keyword to set parameters that restrict a user network access to privileged EXEC mode.

The aaa authorization exec tacacs+ local command sets these authorization parameters:

• Use TACACS+ for privileged EXEC access authorization if authentication was performed by using TACACS+
• Use the local database if authentication was not performed by using TACACS+.

To determine the privilege level as a logged-in user, type the show privilege command.
To determine what commands are available at a particular privilege level for the version of Cisco IOS® software that you are using, type a ? at the command line when logged in at that privilege level.

Note: Instead of assigning privilege levels, you can do command authorization if the authentication server supports TACACS+. The RADIUS protocol does not support command authorization.
!
In this example,

snmp-server
commands are moved down from privilege level 15 (the default) to privilege level 7.
!
The ping command is moved up from privilege level 1 to privilege level 7.
!
When user seven is authenticated, that user is assigned privilege level 7 by the server and a show privilege command displays “Current privilege level is 7.” The user can ping and do snmp-server configuration in configuration mode. Other configuration commands are not available.
!
Configurations – Router :

aaa new-model
aaa authentication login default group tacacs+|radius local
aaa authorization exec default group tacacs+|radius local
username backup privilege 7 password 0 backup
tacacs-server host 171.68.118.101
tacacs-server key cisco
radius-server host 171.68.118.101
radius-server key cisco
privilege configure level 7 snmp-server host
privilege configure level 7 snmp-server enable
privilege configure level 7 snmp-server
privilege exec level 7 ping
privilege exec level 7 configure terminal
privilege exec level 7 configure
}
}
Cisco Secure UNIX TACACS+
Follow these steps to configure the server.
!
user = seven {
password = clear “seven”
service = shell {
set priv-lvl = 7
}
}
Cisco Secure NT RADIUS
Follow these steps to configure the server.
!
Enter the username and password.
In the Group Settings for IETF, Service-type (attribute 6) = Nas-Prompt
In the Cisco RADIUS area, check AV-Pair, and in the rectangular box underneath, enter shell:priv-lvl=7.

}
}

Cisco Secure UNIX RADIUS
user = seven{
radius=Cisco {
check_items= {
2=”seven”
}
reply_attributes= {
6=7
9,1=”shell:priv-lvl=7“
}
}
}
This is the user file for the username “seven.”
Note: The server must support Cisco av-pairs.
seven Password = passwdxyz
Service-Type = Shell-User
cisco-avpair =shell:priv-lvl=7

Cisco TACACS Configuration

aaa new model
aaa authentication login default group tacacs+ local enable
aaa authorization exec default group tacacs+ local none
aaa authorization commands 0 default group tacacs+ local none
aaa authorization commands 1 default group tacacs+ local none
aaa authorization commands 15 default group tacacs+ local none
aaa accounting exec default start-stop group tacacs+
aaa accounting commands 0 default start-stop group tacacs+
aaa accounting commands 1 default start-stop group tacacs+
aaa accounting commands 15 default start-stop group tacacs+
aaa session-id common
!
tacacs-server host 1.1.1.1
tacacs-server directed-request
tacacs-server key 0 C0mm5