This reference section includes examples of various TACACS+ operational command outputs used to monitor and troubleshoot router transactions during AAA operations. Use these examples to identify outputs that report TACACS+ request counts, failures, errors, timeouts, server state, and source-interface details. The outputs can help verify operational health and confirm that the counters reset as expected after using clear commands.
TACACS+ counters output
The TACACS+ counters output records the number of requests, timeouts, failures, errors, and successes for each TACACS+ server across all AAA services.
plaintext:Y
Router:ios# show tacacs counters
TACACS+ Server: 10.105.236.101/4010 [global]
Authentication:
10 requests, 4 accepts, 3 failure, 2 error, 1 timeout
Exec Authorization:
0 requests, 0 accepts, 0 denied, 0 error, 0 timeout
Command Authorization:
6 requests, 6 accepts, 0 denied, 0 error, 0 timeout
Exec Accounting:
0 requests, 0 accepts, 0 fail, 0 error, 0 timeout
Command Accounting:
6 requests, 6 accepts, 0 fail, 0 error, 0 timeout
TACACS+ Server: 10.105.236.101/2201 [private] vrf = default
Authentication:
0 requests, 0 accepts, 0 failure, 0 error, 0 timeout
Exec Authorization:
0 requests, 0 accepts, 0 denied, 0 error, 0 timeout
Command Authorization:
0 requests, 0 accepts, 0 denied, 0 error, 0 timeout
Exec Accounting:
0 requests, 0 accepts, 0 fail, 0 error, 0 timeout
Command Accounting:
0 requests, 0 accepts, 0 fail, 0 error, 0 timeout
TACACS+ details output
The TACACS+ details output includes server group, source interface, individual server statistics, packet counters, connection opens and closes, and TCP connection indicators.
plaintext:Y
Router:ios# show tacacs details
TACACS+ Server : 10.105.236.101/4010 [Global]
Family : IPv4
Timeout(in secs) : 3
Connection Opens : 8
Connection Closes : 8
Requests sent : 6
Response received : 6
Packets Abort : 2
Server State : Down
Server On-Hold : True
Tacacs-Single-Connect : False
Tacacs-Single-Connect-Idle-Timeout(in secs) : 0
Last Connection Attempted : 08:32:43 UTC Tue Aug 02 2022
TACACS+ Server : 10.105.236.101/8010 [Private] vrf=default
Family : IPv4
Timeout(in secs) : 3
Connection Opens : 8
Connection Closes : 7
Requests sent : 7
Response received : 7
Packets Abort : 0
Server State : Up
Server On-Hold : False
Tacacs-Single-Connect : False
Tacacs-Single-Connect-Idle-Timeout(in secs) : 0
Last Connection Attempted : 08:32:52 UTC Tue Aug 02 2022
TACACS+ Server-groups:
Global list of servers
Server 10.105.236.101/4010 family=IPv4
Server group 'tac1' has 1 servers
Servers in this group are under 'default' vrf
Server 10.105.236.101/8010 [private] family=IPv4
TACACS+ Source-Interface:
Interface VRF Id IPV4-Address
GigabitEthernet0/0/0/0 0x60000001 0.0.0.0
MgmtEth0/RP0/CPU0/0 0x60000000 192.168.122.222
Interface VRF Id IPV6-Address
GigabitEthernet0/0/0/0 0x60000001 ::
MgmtEth0/RP0/CPU0/0 0x60000000 ::
TACACS+ source-interface output
The TACACS+ source-interface output displays the source interface and corresponding IP addresses for TACACS+ transactions.
plaintext:Y
Router:ios# show tacacs source-interfaces
Interface VRF Id IPV4-Address
MgmtEth0/RP0/CPU0/0 0x60000000 192.168.122.222
Interface VRF Id IPV6-Address
MgmtEth0/RP0/CPU0/0 0x60000000 ::
Clear TACACS+ counters output
To clear all AAA services counters reported by the show tacacs counters command for all TACACS+ servers, use the clear tacacs counters command:
plaintext:Y
Router:ios# show tacacs counters
TACACS+ Server: 10.105.236.101/4010 [global]
Authentication:
10 requests, 4 accepts, 3 failure, 2 error, 1 timeout
Exec Authorization:
0 requests, 0 accepts, 0 denied, 0 error, 0 timeout
Command Authorization:
6 requests, 6 accepts, 0 denied, 0 error, 0 timeout
Exec Accounting:
0 requests, 0 accepts, 0 fail, 0 error, 0 timeout
Command Accounting:
6 requests, 6 accepts, 0 fail, 0 error, 0 timeout
TACACS+ Server: 10.105.236.101/2201 [private] vrf = default
Authentication:
0 requests, 0 accepts, 0 failure, 0 error, 0 timeout
Exec Authorization:
0 requests, 0 accepts, 0 denied, 0 error, 0 timeout
Command Authorization:
0 requests, 0 accepts, 0 denied, 0 error, 0 timeout
Exec Accounting:
0 requests, 0 accepts, 0 fail, 0 error, 0 timeout
Command Accounting:
0 requests, 0 accepts, 0 fail, 0 error, 0 timeout
Router:ios# clear tacacs counters
Router:ios# show tacacs counters
TACACS+ Server: 10.105.236.101/4010 [global]
Authentication:
0 requests, 0 accepts, 0 failure, 0 error, 0 timeout
Exec Authorization:
0 requests, 0 accepts, 0 denied, 0 error, 0 timeout
Command Authorization:
0 requests, 0 accepts, 0 denied, 0 error, 0 timeout
Exec Accounting:
0 requests, 0 accepts, 0 fail, 0 error, 0 timeout
Command Accounting:
0 requests, 0 accepts, 0 fail, 0 error, 0 timeout
TACACS+ Server: 10.105.236.101/2201 [private] vrf = default
Authentication:
0 requests, 0 accepts, 0 failure, 0 error, 0 timeout
Exec Authorization:
0 requests, 0 accepts, 0 denied, 0 error, 0 timeout
Command Authorization:
0 requests, 0 accepts, 0 denied, 0 error, 0 timeout
Exec Accounting:
0 requests, 0 accepts, 0 fail, 0 error, 0 timeout
Command Accounting:
0 requests, 0 accepts, 0 fail, 0 error, 0 timeout
How to use these outputs
-
Use the counters and details outputs to monitor TACACS+ service health and validate router interaction.
-
Check after clearing counters to confirm reset success and verify current request and error activity.