{"id":1956,"date":"2011-04-12T19:46:03","date_gmt":"2011-04-12T19:46:03","guid":{"rendered":"http:\/\/wiki.freeiz.com\/?p=1956"},"modified":"2016-08-09T12:08:39","modified_gmt":"2016-08-09T12:08:39","slug":"centralizing-logins-with-tacacs","status":"publish","type":"post","link":"https:\/\/wiki-see.info\/wp\/2011\/04\/12\/centralizing-logins-with-tacacs\/","title":{"rendered":"Centralizing Logins with TACACS+"},"content":{"rendered":"<p><strong><span style=\"color: #800000;\">C<\/span><span style=\"color: #000000;\"><span style=\"color: #800000;\">onfiguring TACACS<\/span>+<\/span><\/strong><span style=\"color: #000000;\"> can be a bit of a challenge if you have never done it before.<br \/>\nBut once you understand the format of the config file its really pretty simple<\/span>.<\/p>\n<p><span style=\"color: #000080;\">Here&#8217;s a sample tacacs+ config<\/span> :<\/p>\n<pre><span style=\"color: #000000;\"># Encryption key is the same key you configure in your router\n# ENCYPTION KEY:<\/span>\n\t<span style=\"color: #800000;\">key = <em>password<\/em><\/span>\n\n<span style=\"color: #000000;\"># You will want to log access to a file. Set that file here\n# Remember to rotate the log, it will grow over time.\n# write accounting to:<\/span>\n\t<span style=\"color: #800000;\">accounting file = accounting.log<\/span>\n\n<span style=\"color: #000000;\">#########################################\n###############Users#####################\n#########################################<\/span>\n\n<span style=\"color: #000000;\">### without \"login = \" need to authenticate through radius or local:\n\n\t<span style=\"color: #000000;\">user \t= tom <\/span>\t\t{ <span style=\"color: #800000;\">member = itnetwork<\/span> }\n\t<span style=\"color: #000000;\">user \t= dick<\/span>\t\t{ <span style=\"color: #800000;\">member = itnetwork<\/span> }\n\t<span style=\"color: #000000;\">user \t= harry\t<\/span>\t{ <span style=\"color: #800000;\">member = itnetwork<\/span> }\n<\/span>\n\t<span style=\"color: #000000;\">user\t= backup-user\t{ member = show } # show profile for only doing backups<\/span>\n\n<span style=\"color: #000000;\">################################\n##########Groups################\n################################<\/span>\n\n<span style=\"color: #000000;\"><span style=\"color: #800000;\">group = itnetwork<\/span> {\n\t\t# IT-Network Engineers\n        login = file passwords.db\n\n\t\tservice\t= exec {\n\t\t\tdefault attribute = permit\n\t\t\t<span style=\"color: #800000;\">priv-lvl = 15<\/span>\n\t\t}\n\ncmd = show {\n                permit .*\n                }\ncmd = enable {\n                permit .*\n                }\n#################################################\n# The remainder edited for breavity<\/span><\/pre>\n<p><span style=\"color: #000000;\">In the above sample config there are basically three sections.\u00a0 The top section of the config is<br \/>\nwhere you define the <em><span style=\"color: #000080;\">encryption key <\/span><\/em>that allows your routers and switches to authenticate to<br \/>\nyour tacacs+ server.<\/span><\/p>\n<p><span style=\"color: #000000;\">The next section is the users section.\u00a0 This is where you define the user names , which group they<br \/>\nare a <span style=\"color: #800000;\">member of<\/span>, and where the <span style=\"color: #800000;\">password<\/span> is kept.\u00a0 In this example we are using a file called<br \/>\n<em><span style=\"color: #800000;\">passwords.db<\/span><\/em> that contains these<span style=\"color: #800000;\"> passwords<\/span>.<\/span><\/p>\n<p><span style=\"color: #000000;\">Finally is the <span style=\"color: #800000;\">group section<\/span>.\u00a0 This is where you define the commands that can be executed by<br \/>\nthis <span style=\"color: #800000;\">group<\/span>. Users can belong to <span style=\"color: #800000;\">multiple groups<\/span>.\u00a0 Commands can be <span style=\"color: #800000;\">permitted<\/span> or <span style=\"color: #800000;\">denied<\/span> which<br \/>\nallows for an amazing amount of control over what users and groups can do on your network devices.<\/span><\/p>\n<p><span style=\"color: #000000;\">While TAC+ runs on the server, enter this command on the server to see the entries that go into the<br \/>\naccounting file:<\/span><\/p>\n<p><span style=\"color: #800000;\">tail -f \/var\/log\/tac.log <\/span><\/p>\n<p><span style=\"color: #000000;\"><strong>For more advanced features check out Cisco Secure ACS Server.<\/strong><\/span><\/p>\n<p><strong> <\/strong><\/p>\n<p><strong><span style=\"color: #333333; font-family: Arial, Tahoma, Verdana; line-height: 20px; font-weight: normal;\"><span style=\"color: #000000;\">The entire tacacs+ package can be <\/span><a style=\"color: #2255aa; text-decoration: none;\" href=\"http:\/\/wiki.freeiz.com\/tac.cfg\">downloaded here<\/a><span style=\"font-family: Arial, Tahoma, Verdana;\">. <\/span><span style=\"color: #000000;\"> It contains the entire tac.cfg file<\/span><\/span><\/strong><\/p>\n<div id=\"_mcePaste\"><strong> <\/strong><\/div>\n","protected":false},"excerpt":{"rendered":"<p>Configuring TACACS+ can be a bit of a challenge if you have never done it before. But once you understand the format of the config file its really pretty simple. Here&#8217;s a sample tacacs+ config : # Encryption key is the same key you configure in your router # ENCYPTION KEY: key = password # [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[8],"tags":[666],"class_list":["post-1956","post","type-post","status-publish","format-standard","hentry","category-linux","tag-tacacs"],"_links":{"self":[{"href":"https:\/\/wiki-see.info\/wp\/wp-json\/wp\/v2\/posts\/1956","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wiki-see.info\/wp\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/wiki-see.info\/wp\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/wiki-see.info\/wp\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/wiki-see.info\/wp\/wp-json\/wp\/v2\/comments?post=1956"}],"version-history":[{"count":1,"href":"https:\/\/wiki-see.info\/wp\/wp-json\/wp\/v2\/posts\/1956\/revisions"}],"predecessor-version":[{"id":5091,"href":"https:\/\/wiki-see.info\/wp\/wp-json\/wp\/v2\/posts\/1956\/revisions\/5091"}],"wp:attachment":[{"href":"https:\/\/wiki-see.info\/wp\/wp-json\/wp\/v2\/media?parent=1956"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/wiki-see.info\/wp\/wp-json\/wp\/v2\/categories?post=1956"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/wiki-see.info\/wp\/wp-json\/wp\/v2\/tags?post=1956"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}