Explains securing TACACS+ with TLS protection by detailing security benefits, operational workflows, supported and unsupported requirements, and configuration steps for implementing TLS in TACACS+ deployments.
A TACACS+ with TLS protection is a security enhancement that
-
encrypts TACACS+ AAA communication between network devices and TACACS+ servers using Transport Layer Security (TLS)
-
provides confidentiality and integrity for sensitive AAA data transmitted over potentially insecure networks, and
-
supports mutual authentication between the client and server through TLS X.509 certificates and is compatible with TLS versions 1.3 and 1.2.
Feature history
The feature history table lists release support for this feature.
|
Feature Name |
Release Information |
Feature Description |
|---|---|---|
|
TACACS+ with TLS protection |
Release 25.3.1 |
Introduced in this release on: Fixed Systems (8200 [ASIC: Q100, Q200, P100], 8700 [ASIC: P100, K100], 8010 [ASIC: A100]); Centralized Systems (8600 [ASIC: Q200]); Modular Systems (8800 [LC ASIC: Q100, Q200, P100]) You can significantly enhance security and reduce the risk of attacks on weak encryption by using TACACS+ over TLS. This method ensures the secure transmission of all Authentication, Authorization, and Accounting (AAA) data between the client and server. It provides robust protection for sensitive environments by supporting mutual authentication through a TLS X.509 certificate-based infrastructure. This feature is compatible with both TLS versions 1.3 and 1.2. |