System Security Configuration Guide for Cisco 8000 Series Routers, IOS XR Releases

PDF

System Security Configuration Guide for Cisco 8000 Series Routers, IOS XR Releases

TACACS+ with TLS protection

Want to summarize with AI?

Log in

Explains securing TACACS+ with TLS protection by detailing security benefits, operational workflows, supported and unsupported requirements, and configuration steps for implementing TLS in TACACS+ deployments.


A TACACS+ with TLS protection is a security enhancement that

  • encrypts TACACS+ AAA communication between network devices and TACACS+ servers using Transport Layer Security (TLS)

  • provides confidentiality and integrity for sensitive AAA data transmitted over potentially insecure networks, and

  • supports mutual authentication between the client and server through TLS X.509 certificates and is compatible with TLS versions 1.3 and 1.2.

Feature history

The feature history table lists release support for this feature.

Table 1. Feature History Table

Feature Name

Release Information

Feature Description

TACACS+ with TLS protection

Release 25.3.1

Introduced in this release on: Fixed Systems (8200 [ASIC: Q100, Q200, P100], 8700 [ASIC: P100, K100], 8010 [ASIC: A100]); Centralized Systems (8600 [ASIC: Q200]); Modular Systems (8800 [LC ASIC: Q100, Q200, P100])

You can significantly enhance security and reduce the risk of attacks on weak encryption by using TACACS+ over TLS. This method ensures the secure transmission of all Authentication, Authorization, and Accounting (AAA) data between the client and server. It provides robust protection for sensitive environments by supporting mutual authentication through a TLS X.509 certificate-based infrastructure. This feature is compatible with both TLS versions 1.3 and 1.2.


Security benefits provided by TACACS+ with TLS protection

The security benefits of TACACS+ with TLS protection include:

  • Encrypted communication: Enhances security by encrypting all TACACS+ traffic between clients and servers.

  • Data protection: Protects AAA data with robust encryption, reducing risk of interception or tampering.

  • Mutual authentication: Supports mutual authentication between client and server, preventing unauthorized access and impersonation.

  • TLS standards compliance: Complies with TLS 1.3 and 1.2 standards to ensure strong, modern cryptographic protocols.

Use this reference to identify the security benefits that TACACS+ with TLS protection provides. Apply these benefits when selecting TACACS+ transport protection for sensitive AAA environments.


How TACACS+ with TLS protection works

The use of TLS protection for TACACS+ is critical in environments where sensitive AAA information must be secured from potential interception or tampering. By wrapping TACACS+ packets in an encrypted TLS tunnel, organizations safeguard both user credentials and authorization events during SSH remote access.

Summary

The key components involved in the process are:

  • End user: Initiates an SSH session to access the network device.

  • Router as TACACS+ TLS client: Receives the AAA service request and initiates a TLS session with the TACACS+ server.

  • TACACS+ server: Uses valid TLS configuration, terminates the TLS session, and processes AAA requests and responses.

  • TLS session: Encrypts the TACACS+ traffic between the client and server.

  • TACACS+ packets: Carry authentication, authorization, and accounting information over the TLS tunnel.

TACACS+ with TLS protection enhances network security by establishing an encrypted TLS session between a router and a TACACS+ server whenever a user initiates SSH access. This ensures all AAA traffic is protected during communication.

Workflow

These stages describe how TACACS+ with TLS protection works.

  1. Session initiation: The end user initiates an SSH session to the network device.

  2. AAA request: The router receives the user's AAA service request for TACACS+ with TLS protection.

  3. TLS establishment: If the TACACS+ server has valid TLS settings, the router and server establish a TLS session.

  4. Secure exchange: The router and TACACS+ server exchange TACACS+ packets over the encrypted TLS session.

Result

The process establishes a secure, encrypted channel for TACACS+ traffic, ensuring AAA communications remain protected during SSH access.


Requirement: You must use supported TACACS+ TLS practices

You must follow these requirements when configuring TACACS+ with TLS protection:

  • Configure the destination port for TACACS+ with TLS protection; do not use separate ports for authentication, accounting, or authorization.

  • Use TLS X.509 certificate-based mutual authentication between client and server.

  • Use only TLS version 1.3 (as mandated by RFC 8446) or TLS version 1.2.

  • Choose either multi-connect or single connect modes without TLS resumption, as required by your environment.

  • Ensure you implement the cipher suites mandated by TLS 1.3 and TLS 1.2.

  • Use IPv4 or IPv6 for TACACS+ transactions, based on your network configuration.

  • Configure the source interface and non-default Virtual Routing and Forwarding (VRF), if required by your topology.

  • Set the connection timer and single-connect idle timeout as needed; these settings work the same as for TACACS+ over TCP.


Requirement: Avoid unsupported TACACS+ TLS behavior

Cisco IOS XR imposes strict requirements concerning unsupported behaviors when configuring TACACS+ with TLS protection. You must comply with the following:

  • Do not use the TACACS+ encryption method supported in Cisco IOS XR software releases earlier than 25.3.1—it is unsupported.

  • Never mix non-TLS and TLS servers in the same TACACS+ server group.

  • Do not enable TLS session resumption or use TLS sessions with PSK cipher suites; these are unsupported.


Configure TACACS+ with TLS protection

Enable TLS for TACACS+ server communication so that authentication, authorization, and accounting traffic is encrypted.

Use TLS to secure TACACS+ server communication, either directly on a TACACS+ host or within an AAA server group. Afterwards, verify the TLS protection state.

Before you begin

Configure the TACACS+ server and trustpoint information before enabling TLS.

Procedure

  1. Enable TLS for TACACS+ server communication.

    TACACS+ server host configuration:

    Example:

    Router(config)# tacacs-server host 10.105.236.101 port 4950
    Router(config-tacacs-host)# tls
    Router(config-tacacs-host-tls)# server-name-indicator aaa.cisco.com
    Router(config-tacacs-host-tls)# trustpoint test
    Router(config-tacacs-host-tls)# commit

    Server-group configuration:

    Example:

    Router(config)# configure
    Router(config)# aaa group server tacacs+ tac1
    Router(config-sg-tacacs)# server-private 10.105.236.101 port 2345
    Router(config-sg-tacacs-private)# tls
    Router(config-sg-tacacs-private-tls)# server-name-indicator aaa.cisco.com
    Router(config-sg-tacacs-private-tls)# trustpoint abc
    Router(config-sg-tacacs-private-tls)# commit
    • TACACS+ server host configuration:

    • Server-group configuration:

  2. Display TACACS+ TLS operational information.

    Example:

    Router# show tacacs
    Info: Verify that TACACS+ with TLS protection is configured.
    
    Server: 10.105.236.101/2084
    .....
    FIPS mode : TRUE/FALSE.
    TLS:
       Version: TLS 1.3/1.2      // only for active connection
       Cipher: TLS_AES_128_GCM_SHA256  // only for active connection
    Statistics:
       Successful connections: 0
       Failed connections         : 0
       SSL  errors :
        Connect error:
        Read error:
        Write error:
        Handshake Failure:
        Protocol Mismatch :
      Certificate Validation Error:
      Cipher Suite Mismatch:
      Session Timeout:
      Revoked Certificate:
      Unsupported TLS Version:
      Untrusted CA:

TLS secures TACACS+ communication with the specified server.