Fortinet black logo

TACACS+ authentication

TACACS+ authentication

You can add, update, and delete TACACS+ authentication settings.

Add TACACS+ authentication settings

  1. Select tacacs+ from the Auth Server Settings dropdown menu.
  2. Right-click in the TACACS+ authentication table and select Create New.
  3. Enter values in the relevant fields. See TACACS+ authentication fields.
  4. Select Save.

Update TACACS+ authentication settings

  1. Select tacacs+ from the Auth Server Settings dropdown menu.
  2. Right-click a TACACS+ server and select Edit.
  3. Update the values that you want to change.
  4. Select Save.

Delete TACACS+ authentication settings

  1. Select tacacs+ from the Auth Server Settings dropdown menu.
  2. Right-click a TACACS+ server and select Delete.
  3. Select Yes in the confirmation dialog box to delete the selected server.

TACACS+ authentication fields

The Create New TACACS+and Edit TACACS+ dialogs contain the following fields:

Settings

Guidelines

Name

Required. The TACACS+ server name.

Authentication Type

Authentication methods/protocols permitted for this TACACS+ server:

auto—Use PAP, MSCHAP, and CHAP (in that order).

ms_chap—Microsoft Challenge Handshake Authentication Protocol.

chap—Challenge Handshake Authentication Protocol.

ascii—ASCII.

pap—Password Authentication Protocol.

Authorization

Enable or disable TACACS+ authorization.

Key

The key to access the primary server.

Port

The port number of the TACACS+ server.

Secondary Key

The key to access the secondary server.

Secondary Server

The CN domain name or IP address for the secondary TACACS+ server.

Server

Required. The CN domain name or IP address for the primary TACACS+ server.

Source Ip

The source IP address for communications to TACACS+ server.

Tertiary Key

The key to access the tertiary server.

Tertiary Server

The CN domain name or IP address for the tertiary TACACS+ server.

TACACS+ authentication

You can add, update, and delete TACACS+ authentication settings.

Add TACACS+ authentication settings

  1. Select tacacs+ from the Auth Server Settings dropdown menu.
  2. Right-click in the TACACS+ authentication table and select Create New.
  3. Enter values in the relevant fields. See TACACS+ authentication fields.
  4. Select Save.

Update TACACS+ authentication settings

  1. Select tacacs+ from the Auth Server Settings dropdown menu.
  2. Right-click a TACACS+ server and select Edit.
  3. Update the values that you want to change.
  4. Select Save.

Delete TACACS+ authentication settings

  1. Select tacacs+ from the Auth Server Settings dropdown menu.
  2. Right-click a TACACS+ server and select Delete.
  3. Select Yes in the confirmation dialog box to delete the selected server.

TACACS+ authentication fields

The Create New TACACS+and Edit TACACS+ dialogs contain the following fields:

Settings

Guidelines

Name

Required. The TACACS+ server name.

Authentication Type

Authentication methods/protocols permitted for this TACACS+ server:

auto—Use PAP, MSCHAP, and CHAP (in that order).

ms_chap—Microsoft Challenge Handshake Authentication Protocol.

chap—Challenge Handshake Authentication Protocol.

ascii—ASCII.

pap—Password Authentication Protocol.

Authorization

Enable or disable TACACS+ authorization.

Key

The key to access the primary server.

Port

The port number of the TACACS+ server.

Secondary Key

The key to access the secondary server.

Secondary Server

The CN domain name or IP address for the secondary TACACS+ server.

Server

Required. The CN domain name or IP address for the primary TACACS+ server.

Source Ip

The source IP address for communications to TACACS+ server.

Tertiary Key

The key to access the tertiary server.

Tertiary Server

The CN domain name or IP address for the tertiary TACACS+ server.