- About This Guide
-
- Information about AAA
- Configuring the Local Database for AAA
- Configuring RADIUS Servers for AAA
- Configuring TACACS+ Servers for AAA
- Configuring LDAP Servers for AAA
- Configuring Windows NT Servers for AAA
- Configuring the Identity Firewall
- Configuring the ASA to Integrate with Cisco TrustSec
- Configuring Digital Certificates
- Index
Configuring TACACS+ Servers for AAA
This chapter describes how to configure TACACS+ servers used in AAA and includes the following sections:
Information About TACACS+ Servers
The ASA supports TACACS+ server authentication with the following protocols: ASCII, PAP, CHAP, and MS-CHAPv1.
Using TACACS+ Attributes
The ASA provides support for TACACS+ attributes. TACACS+ attributes separate the functions of authentication, authorization, and accounting. The protocol supports two types of attributes: mandatory and optional. Both the server and client must understand a mandatory attribute, and the mandatory attribute must be applied to the user. An optional attribute may or may not be understood or used.

Note To use TACACS+ attributes, make sure that you have enabled AAA services on the NAS.
Table 35-1 lists supported TACACS+ authorization response attributes for cut-through-proxy connections. Table 35-2 lists supported TACACS+ accounting attributes.
Licensing Requirements for TACACS+ Servers
|
|
---|---|
Guidelines and Limitations
This section includes the guidelines and limitations for this feature.
Supported in single and multiple context mode.
Supported in routed and transparent firewall mode.
- You can have up to 100 server groups in single mode or 4 server groups per context in multiple mode.
- Each group can have up to 16 servers in single mode or 4 servers in multiple mode.
- If you need to configure fallback support using the local database, see the “Fallback Support” and the “How Fallback Works with Multiple Servers in a Group”.
- To prevent lockout from the ASA when using TACACS+ authentication or authorization, see the “Recovering from a Lockout”.
Configuring TACACS+ Servers
This section includes the following topics:
- Task Flow for Configuring TACACS+ Servers
- Configuring TACACS+ Server Groups
- Adding a TACACS+ Server to a Group
Task Flow for Configuring TACACS+ Servers
Step 1 Add a TACACS+ server group. See the “Configuring TACACS+ Server Groups” section.
Step 2 For a server group, add a server to the group. See the “Adding a TACACS+ Server to a Group” section.
Configuring TACACS+ Server Groups
If you want to use a TACACS+ server for authentication, authorization, or accounting, you must first create at least one TACACS+ server group and add one or more servers to each group. You identify TACACS+ server groups by name.
Detailed Steps
Examples
The following example shows how to add one TACACS+ group with one primary and one backup server:
Adding a TACACS+ Server to a Group
To add a TACACS+ server to a group, perform the following steps:
Detailed Steps
Monitoring TACACS+ Servers
To monitor TACACS+ servers,enter one of the following commands:
Feature History for TACACS+ Servers
Table 35-3 lists each feature change and the platform release in which it was implemented.