TAACS+ Parameters
The TACACS+ parameters are described in the table below.
TACACS+ Parameters
|
Parameter |
Description |
|||||||||
|---|---|---|---|---|---|---|---|---|---|---|
|
'Enable for Login' configure system > tacacs-settings > authentication > login-tacacs-plus [TacPlusEnable] |
Enables TACACS+ user authentication for the Web interface and CLI.
|
|||||||||
|
'Use TACACS+ Privilege Level' configure system > tacacs-settings > authorization > login-tacacs-plus [TacPlusLoginAuthorizationEnable] |
Enables TACACS+ user authorization (privilege level) for the Web interface and CLI.
|
|||||||||
|
'Default Access Level' configure system > tacacs-settings > authorization > default-access-level [TacPlusDefaultAccessLevel] |
Defines which user (access) level the device assigns to the user if no mapping exists between the received TACACS+ privilege level from the TACACS+ server and the device's user level. The device maps the TACACS+ privilege level according to the TACACS+ Access Level Mapping table. For more information, see Configuring TACACS+ Access Level Mapping.
|
|||||||||
|
'Fallback to Local Users' configure system > tacacs-settings > authentication > login-tacacs-plus-local [TacPlusFallbackToLocalUsers] |
Defines if the device falls back to authentication through local user accounts (Local Users table) if TACACS+ authentication fails.
To configure local users, see Configuring Local Management User Accounts. |
|||||||||
|
'Accounting Login/Logout' configure system > tacacs-settings > accounting > exec-start-stop-tacacs-plus [TacPlusLoginAccountingEnable] |
Enables the device to send session -level accounting records to the TACACS+ server whenever a user logs in to or logs out of the Web interface or CLI. The device sends a start-record accounting notice when the session starts (i.e., user logs in) and a stop-record when the session ends (i.e., user logs out).
|
|||||||||
|
configure system > tacacs-settings > accounting > command-start-stop-tacacs-plus [TacPlusCmdAccountingEnable] |
Enables the device to send CLI command-level accounting records to the TACACS+ server whenever a user executes a command.
|
|||||||||
|
'Consider TACACS+ Error Response as Failure' configure system > tacacs-settings > authentication > error-response-consider-as-failure [TacPlusErrorResponseConsiderAsFailure] |
Enables the device to handle a received TACACS+ ERROR response as an authentication failure.
|
|||||||||
|
configure system > tacacs-settings > authorization > enable-if-authenticated-tacacs-plus [TacPlusLocalAuthorizationEnable_c] |
Enables the use of the local password for CLI Privileged mode when the user is authenticated by TACACS+.
|
|||||||||
|
system > tacacs-settings > authorization > command-tacacs-plus [TacPlusCmdAuthorizationEnable] |
Enables TACACS+ for CLI command authorization, determining if the user is allowed to execute a specific command.
|
|||||||||
|
configure system > tacacs-settings > authentication > login-tacacs-plus-allow-console-bypass-authentication [TacBypassEnable] |
Enables bypassing TACACS+ authentication when the user logs into the device through serial communication.
|
|||||||||
|
configure system > tacacs-settings > authentication > login-tacacs-plus-allow-console-bypass-authentication-authorization [TacPlusPrivilegedBypassEnable] |
Enables bypassing TACACS+ authorization (privilege level) for accessing the CLI Privileged mode when the user is logged into the device through serial communication.
|