<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cisco Router as Terminal/Comm Server - TTY Line TACACS Authenticat in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/cisco-router-as-terminal-comm-server-tty-line-tacacs/m-p/4890946#M583001</link>
    <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot (983).png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/192346iC5956DA0B2AEBA19/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot (983).png" alt="Screenshot (983).png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.geeksforgeeks.org/difference-between-tacacs-and-radius/" target="_blank"&gt;Difference between TACACS+ and RADIUS - GeeksforGeeks&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;All the AAA packets are encrypted in TACACS+ &amp;lt;&amp;lt;- the packet is encrypted in tacacs that why we can not see password&amp;nbsp;or username&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 24 Jul 2023 10:05:23 GMT</pubDate>
    <dc:creator>MHM Cisco World</dc:creator>
    <dc:date>2023-07-24T10:05:23Z</dc:date>
    <item>
      <title>Cisco Router as Terminal/Comm Server - TTY Line TACACS Authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-router-as-terminal-comm-server-tty-line-tacacs/m-p/4889639#M582969</link>
      <description>&lt;P&gt;Hello community,&lt;/P&gt;
&lt;P&gt;I have a question about securing the TTY lines on a Cisco router as a terminal server with TACACS authentication.&lt;/P&gt;
&lt;P&gt;Is it normal that no username is sent when authenticating on the TTY line? (see debug output below the configuration)&lt;/P&gt;
&lt;P&gt;The configuration looks like this:&lt;/P&gt;
&lt;P&gt;--------------------------------------------------------------------------------------------------------------&lt;/P&gt;
&lt;P&gt;aaa new-model&lt;BR /&gt;!&lt;BR /&gt;aaa authentication login default group ffmaaa local&lt;BR /&gt;aaa authentication enable default group ffmaaa enable&lt;BR /&gt;aaa authorization config-commands&lt;BR /&gt;aaa authorization exec default group ffmaaa local &lt;BR /&gt;aaa authorization commands 1 default group ffmaaa local &lt;BR /&gt;aaa authorization commands 15 default group ffmaaa local &lt;BR /&gt;aaa accounting exec default start-stop group ffmaaa&lt;BR /&gt;aaa accounting commands 0 default start-stop group ffmaaa&lt;BR /&gt;aaa accounting commands 15 default start-stop group ffmaaa&lt;BR /&gt;aaa accounting connection default start-stop group ffmaaa&lt;BR /&gt;!&lt;BR /&gt;aaa group server tacacs+ ffmaaa&lt;BR /&gt;server-private &amp;lt;ip-address&amp;gt; key &amp;lt;key&amp;gt;&lt;BR /&gt;server-private &amp;lt;ip-address&amp;gt; key &amp;lt;key&amp;gt;&lt;BR /&gt;!&lt;BR /&gt;ip host swioob01-04 2068 &amp;lt;ip-address&amp;gt;&lt;BR /&gt;ip host swioob01-05 2070 &amp;lt;ip-address&amp;gt;&lt;BR /&gt;ip host l1201 2072 &amp;lt;ip-address&amp;gt;&lt;BR /&gt;ip host l0601 2073 &amp;lt;ip-address&amp;gt;&lt;BR /&gt;ip host asa01-04 2074 &amp;lt;ip-address&amp;gt;&lt;BR /&gt;ip host asa01-05 2075 &amp;lt;ip-address&amp;gt;&lt;BR /&gt;ip host nx01-04 2076 &amp;lt;ip-address&amp;gt;&lt;BR /&gt;ip host gw01-05 2077 &amp;lt;ip-address&amp;gt;&lt;BR /&gt;ip host nx01-05 2078 &amp;lt;ip-address&amp;gt;&lt;BR /&gt;ip host swi04-04 2079 &amp;lt;ip-address&amp;gt;&lt;BR /&gt;ip host nx01-06 2080 &amp;lt;ip-address&amp;gt;&lt;BR /&gt;ip host nx02-06 2081 &amp;lt;ip-address&amp;gt;&lt;BR /&gt;ip host fraswioob01-12 2066 &amp;lt;ip-address&amp;gt;&lt;BR /&gt;ip host fraoob01-12 2067 &amp;lt;ip-address&amp;gt;&lt;BR /&gt;ip host fraswioob01-06 2069 &amp;lt;ip-address&amp;gt;&lt;BR /&gt;ip host fraoob01-06 2071 &amp;lt;ip-address&amp;gt;&lt;BR /&gt;!&lt;BR /&gt;line 1/0 1/15&lt;BR /&gt;exec-timeout 0 0&lt;BR /&gt;modem InOut&lt;BR /&gt;no exec&lt;BR /&gt;transport input telnet ssh&lt;BR /&gt;stopbits 1&lt;/P&gt;
&lt;P&gt;---------------------------------------------------------------------------------------------------------------&lt;/P&gt;
&lt;P&gt;debug output:&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Jul 19 14:05:48.387 MEST: AAA/AUTHEN/LOGIN (000241DC): Pick method list 'default'&lt;/STRONG&gt; &lt;BR /&gt;Jul 19 14:05:48.391 MEST: TPLUS: Queuing AAA Authentication request 147932 for processing&lt;BR /&gt;Jul 19 14:05:48.391 MEST: TPLUS(000241DC) login timer started 1020 sec timeout&lt;BR /&gt;Jul 19 14:05:48.391 MEST: TPLUS: processing authentication start request id 147932&lt;BR /&gt;Jul 19 14:05:48.391 MEST: TPLUS: Authentication start packet created for 147932()&lt;BR /&gt;Jul 19 14:05:48.391 MEST: TPLUS: Using server &amp;lt;ip-address&amp;gt;&lt;BR /&gt;Jul 19 14:05:48.395 MEST: TPLUS(000241DC)/0/NB_WAIT/4775806C: Started 30 sec timeout&lt;BR /&gt;Jul 19 14:05:48.399 MEST: TPLUS(000241DC)/0/NB_WAIT: socket event 2&lt;BR /&gt;Jul 19 14:05:48.399 MEST: T+: Version 192 (0xC0), type 1, seq 1, encryption 1&lt;BR /&gt;Jul 19 14:05:48.399 MEST: T+: session_id 2056032528 (0x7A8C9110), dlen 27 (0x1B)&lt;BR /&gt;Jul 19 14:05:48.399 MEST: T+: type:AUTHEN/START, priv_lvl:1 action:LOGIN ascii&lt;BR /&gt;Jul 19 14:05:48.399 MEST: T+: svc:LOGIN user_len:0 port_len:7 (0x7) raddr_len:12 (0xC) data_len:0&lt;BR /&gt;&lt;STRONG&gt;Jul 19 14:05:48.399 MEST: T+: user:&lt;/STRONG&gt; &lt;BR /&gt;&lt;STRONG&gt;Jul 19 14:05:48.399 MEST: T+: port: tty1/10&lt;/STRONG&gt;&lt;BR /&gt;Jul 19 14:05:48.399 MEST: T+: rem_addr: &amp;lt;ip-address&amp;gt;&lt;BR /&gt;Jul 19 14:05:48.399 MEST: T+: data: &lt;BR /&gt;Jul 19 14:05:48.399 MEST: T+: End Packet&lt;BR /&gt;Jul 19 14:05:48.403 MEST: TPLUS(000241DC)/0/NB_WAIT: wrote entire 39 bytes request&lt;BR /&gt;Jul 19 14:05:48.403 MEST: TPLUS(000241DC)/0/READ: socket event 1&lt;BR /&gt;Jul 19 14:05:48.403 MEST: TPLUS(000241DC)/0/READ: Would block while reading&lt;BR /&gt;Jul 19 14:05:48.407 MEST: TPLUS(000241DC)/0/READ: socket event 1&lt;BR /&gt;Jul 19 14:05:48.407 MEST: TPLUS(000241DC)/0/READ: read entire 12 header bytes (expect 16 bytes data)&lt;BR /&gt;Jul 19 14:05:48.407 MEST: TPLUS(000241DC)/0/READ: socket event 1&lt;BR /&gt;Jul 19 14:05:48.407 MEST: TPLUS(000241DC)/0/READ: read entire 28 bytes response&lt;BR /&gt;Jul 19 14:05:48.407 MEST: T+: Version 192 (0xC0), type 1, seq 2, encryption 1&lt;BR /&gt;Jul 19 14:05:48.407 MEST: T+: session_id 2056032528 (0x7A8C9110), dlen 16 (0x10)&lt;BR /&gt;Jul 19 14:05:48.407 MEST: T+: AUTHEN/REPLY status:4 flags:0x0 msg_len:10, data_len:0&lt;BR /&gt;&lt;STRONG&gt;Jul 19 14:05:48.407 MEST: T+: msg: username:&lt;/STRONG&gt; &lt;BR /&gt;Jul 19 14:05:48.407 MEST: T+: data: &lt;BR /&gt;Jul 19 14:05:48.407 MEST: T+: End Packet&lt;BR /&gt;Jul 19 14:05:48.407 MEST: TPLUS(000241DC) login timer stopped&lt;BR /&gt;Jul 19 14:05:48.407 MEST: TPLUS(000241DC)/0/4775806C: Processing the reply packet&lt;BR /&gt;Jul 19 14:05:48.411 MEST: TPLUS: Received authen response status GET_USER (7)&lt;BR /&gt;Jul 19 14:05:48.411 MEST: TPLUS(000241DC)/0/None: Started 120 sec timeoutos336164a&lt;BR /&gt;password: &lt;BR /&gt;Jul 19 14:05:53.935 MEST: TPLUS: Queuing AAA Authentication request 147932 for processing&lt;BR /&gt;Jul 19 14:05:53.935 MEST: TPLUS(000241DC) login timer started 1020 sec timeout&lt;BR /&gt;Jul 19 14:05:53.935 MEST: TPLUS: processing authentication continue request id 147932&lt;BR /&gt;Jul 19 14:05:53.935 MEST: TPLUS: Authentication continue packet generated for 147932&lt;BR /&gt;Jul 19 14:05:53.935 MEST: TPLUS(000241DC)/0/None: Timer Stoped &lt;BR /&gt;Jul 19 14:05:53.935 MEST: TPLUS(000241DC)/0/WRITE/47B4A580: Started 30 sec timeout&lt;BR /&gt;Jul 19 14:05:53.935 MEST: T+: Version 192 (0xC0), type 1, seq 3, encryption 1&lt;BR /&gt;Jul 19 14:05:53.935 MEST: T+: session_id 2056032528 (0x7A8C9110), dlen 14 (0xE)&lt;BR /&gt;Jul 19 14:05:53.935 MEST: T+: AUTHEN/CONT msg_len:9 (0x9), data_len:0 (0x0) flags:0x0&lt;BR /&gt;Jul 19 14:05:53.939 MEST: T+: User msg: &amp;lt;elided&amp;gt;&lt;BR /&gt;Jul 19 14:05:53.939 MEST: T+: User data: &lt;BR /&gt;Jul 19 14:05:53.939 MEST: T+: End Packet&lt;BR /&gt;Jul 19 14:05:53.939 MEST: TPLUS(000241DC)/0/WRITE: wrote entire 26 bytes request&lt;BR /&gt;Jul 19 14:05:53.943 MEST: TPLUS(000241DC)/0/READ: socket event 1&lt;BR /&gt;Jul 19 14:05:53.947 MEST: TPLUS(000241DC)/0/READ: read entire 12 header bytes (expect 16 bytes data)&lt;BR /&gt;Jul 19 14:05:53.947 MEST: TPLUS(000241DC)/0/READ: socket event 1&lt;BR /&gt;Jul 19 14:05:53.947 MEST: TPLUS(000241DC)/0/READ: read entire 28 bytes response&lt;BR /&gt;Jul 19 14:05:53.947 MEST: T+: Version 192 (0xC0), type 1, seq 4, encryption 1&lt;BR /&gt;Jul 19 14:05:53.947 MEST: T+: session_id 2056032528 (0x7A8C9110), dlen 16 (0x10)&lt;BR /&gt;Jul 19 14:05:53.947 MEST: T+: AUTHEN/REPLY status:5 flags:0x1 msg_len:10, data_len:0&lt;BR /&gt;Jul 19 14:05:53.947 MEST: T+: msg: password: &lt;BR /&gt;Jul 19 14:05:53.947 MEST: T+: data: &lt;BR /&gt;Jul 19 14:05:53.947 MEST: T+: End Packet&lt;BR /&gt;Jul 19 14:05:53.947 MEST: TPLUS(000241DC) login timer stopped&lt;BR /&gt;Jul 19 14:05:53.947 MEST: TPLUS(000241DC)/0/47B4A580: Processing the reply packet&lt;BR /&gt;Jul 19 14:05:53.947 MEST: TPLUS: Received authen response status GET_PASSWORD (8)&lt;BR /&gt;Jul 19 14:05:53.947 MEST: TPLUS(000241DC)/0/None: Started 120 sec timeout&lt;BR /&gt;Jul 19 14:05:59.671 MEST: TPLUS: Queuing AAA Authentication request 147932 for processing&lt;BR /&gt;Jul 19 14:05:59.675 MEST: TPLUS(000241DC) login timer started 1020 sec timeout&lt;BR /&gt;Jul 19 14:05:59.675 MEST: TPLUS: processing authentication continue request id 147932&lt;BR /&gt;Jul 19 14:05:59.675 MEST: TPLUS: Authentication continue packet generated for 147932&lt;BR /&gt;Jul 19 14:05:59.675 MEST: TPLUS(000241DC)/0/None: Timer Stoped &lt;BR /&gt;Jul 19 14:05:59.675 MEST: TPLUS(000241DC)/0/WRITE/47B4A580: Started 30 sec timeout&lt;BR /&gt;Jul 19 14:05:59.675 MEST: T+: Version 192 (0xC0), type 1, seq 5, encryption 1&lt;BR /&gt;Jul 19 14:05:59.675 MEST: T+: session_id 2056032528 (0x7A8C9110), dlen 18 (0x12)&lt;BR /&gt;Jul 19 14:05:59.675 MEST: T+: AUTHEN/CONT msg_len:13 (0xD), data_len:0 (0x0) flags:0x0&lt;BR /&gt;Jul 19 14:05:59.675 MEST: T+: User msg: &amp;lt;elided&amp;gt;&lt;BR /&gt;Jul 19 14:05:59.675 MEST: T+: User data: &lt;BR /&gt;Jul 19 14:05:59.675 MEST: T+: End Packet&lt;BR /&gt;Jul 19 14:05:59.675 MEST: TPLUS(000241DC)/0/WRITE: wrote entire 30 bytes request&lt;BR /&gt;Jul 19 14:05:59.699 MEST: TPLUS(000241DC)/0/READ: socket event 1&lt;BR /&gt;Jul 19 14:05:59.699 MEST: TPLUS(000241DC)/0/READ: read entire 12 header bytes (expect 6 bytes data)&lt;BR /&gt;Jul 19 14:05:59.699 MEST: TPLUS(000241DC)/0/READ: socket event 1&lt;BR /&gt;Jul 19 14:05:59.699 MEST: TPLUS(000241DC)/0/READ: read entire 18 bytes response&lt;BR /&gt;Jul 19 14:05:59.699 MEST: T+: Version 192 (0xC0), type 1, seq 6, encryption 1&lt;BR /&gt;Jul 19 14:05:59.699 MEST: T+: session_id 2056032528 (0x7A8C9110), dlen 6 (0x6)&lt;BR /&gt;Jul 19 14:05:59.699 MEST: T+: AUTHEN/REPLY status:2 flags:0x0 msg_len:0, data_len:0&lt;BR /&gt;Jul 19 14:05:59.699 MEST: T+: msg: &lt;BR /&gt;Jul 19 14:05:59.699 MEST: T+: data: &lt;BR /&gt;Jul 19 14:05:59.699 MEST: T+: End Packet&lt;BR /&gt;Jul 19 14:05:59.699 MEST: TPLUS(000241DC) login timer stopped&lt;BR /&gt;Jul 19 14:05:59.699 MEST: TPLUS(000241DC)/0/47B4A580: Processing the reply packet&lt;BR /&gt;Jul 19 14:05:59.699 MEST: TPLUS: Received authen response status FAIL (3)&lt;BR /&gt;Jul 19 14:05:59.699 MEST: TPLUS: Invalid Client information received as input&lt;/P&gt;
&lt;P&gt;% Authentication failed&lt;/P&gt;
&lt;P&gt;username: &lt;BR /&gt;J&lt;STRONG&gt;ul 19 14:06:03.703 MEST: AAA/AUTHEN/LOGIN (000241DC): Pick method list 'default'&lt;/STRONG&gt; &lt;BR /&gt;Jul 19 14:06:03.703 MEST: TPLUS: Queuing AAA Authentication request 147932 for processing&lt;BR /&gt;Jul 19 14:06:03.703 MEST: TPLUS(000241DC) login timer started 1020 sec timeout&lt;BR /&gt;Jul 19 14:06:03.703 MEST: TPLUS: processing authentication start request id 147932&lt;BR /&gt;Jul 19 14:06:03.703 MEST: TPLUS: Authentication start packet created for 147932()&lt;BR /&gt;Jul 19 14:06:03.703 MEST: TPLUS: Using server &amp;lt;ip-address&amp;gt;&lt;BR /&gt;Jul 19 14:06:03.707 MEST: TPLUS(000241DC)/0/NB_WAIT/47FEE670: Started 30 sec timeout&lt;BR /&gt;Jul 19 14:06:03.707 MEST: TPLUS(000241DC)/0/NB_WAIT: socket event 2&lt;BR /&gt;Jul 19 14:06:03.707 MEST: T+: Version 192 (0xC0), type 1, seq 1, encryption 1&lt;BR /&gt;Jul 19 14:06:03.707 MEST: T+: session_id 1260940227 (0x4B286BC3), dlen 27 (0x1B)&lt;BR /&gt;&lt;STRONG&gt;Jul 19 14:06:03.707 MEST: T+: type:AUTHEN/START, priv_lvl:1 action:LOGIN ascii&lt;/STRONG&gt;&lt;BR /&gt;Jul 19 14:06:03.707 MEST: T+: svc:LOGIN user_len:0 port_len:7 (0x7) raddr_len:12 (0xC) data_len:0&lt;BR /&gt;&lt;STRONG&gt;Jul 19 14:06:03.707 MEST: T+: user:&lt;/STRONG&gt; &lt;BR /&gt;Jul 19 14:06:03.707 MEST: T+: port: tty1/10&lt;BR /&gt;Jul 19 14:06:03.707 MEST: T+: rem_addr: &amp;lt;ip-address&amp;gt;&lt;BR /&gt;Jul 19 14:06:03.707 MEST: T+: data: &lt;BR /&gt;Jul 19 14:06:03.707 MEST: T+: End Packet&lt;BR /&gt;Jul 19 14:06:03.711 MEST: TPLUS(000241DC)/0/NB_WAIT: wrote entire 39 bytes request&lt;BR /&gt;Jul 19 14:06:03.711 MEST: TPLUS(000241DC)/0/READ: socket event 1&lt;BR /&gt;Jul 19 14:06:03.711 MEST: TPLUS(000241DC)/0/READ: Would block while reading&lt;BR /&gt;Jul 19 14:06:03.715 MEST: TPLUS(000241DC)/0/READ: socket event 1&lt;BR /&gt;Jul 19 14:06:03.715 MEST: TPLUS(000241DC)/0/READ: read entire 12 header bytes (expect 16 bytes data)&lt;BR /&gt;Jul 19 14:06:03.715 MEST: TPLUS(000241DC)/0/READ: socket event 1&lt;BR /&gt;Jul 19 14:06:03.715 MEST: TPLUS(000241DC)/0/READ: read entire 28 bytes response&lt;BR /&gt;Jul 19 14:06:03.715 MEST: T+: Version 192 (0xC0), type 1, seq 2, encryption 1&lt;BR /&gt;Jul 19 14:06:03.715 MEST: T+: session_id 1260940227 (0x4B286BC3), dlen 16 (0x10)&lt;BR /&gt;Jul 19 14:06:03.715 MEST: T+: AUTHEN/REPLY status:4 flags:0x0 msg_len:10, data_len:0&lt;BR /&gt;&lt;STRONG&gt;Jul 19 14:06:03.715 MEST: T+: msg: username:&lt;/STRONG&gt; &lt;BR /&gt;Jul 19 14:06:03.715 MEST: T+: data: &lt;BR /&gt;Jul 19 14:06:03.715 MEST: T+: End Packet&lt;/P&gt;
&lt;P&gt;-------------------------------------------------------------------------------------------------------------&lt;/P&gt;
&lt;P&gt;On the Cisco ISE we use for TACACS as a condition for the desired policy that a TACACS request comes and the username should start with "os" or "ex".&lt;/P&gt;
&lt;P&gt;This policy on the ISE is skipped because no username is sent with the authentication on the TTY line and the condition therefore does not apply.&lt;/P&gt;
&lt;P&gt;Of course, the policy could be designed differently, but the primary issue is why no username is sent.&lt;/P&gt;
&lt;P&gt;Can this be influenced?&lt;/P&gt;
&lt;P&gt;What is best practice for implementing authentication / authorization for the TTY lines?&lt;BR /&gt;Maybe even examples for a suitable policy set (Authentication / Authorization Policy)&lt;/P&gt;
&lt;P&gt;Best regards,&lt;/P&gt;
&lt;P&gt;Stephan&lt;/P&gt;</description>
      <pubDate>Fri, 21 Jul 2023 11:07:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-router-as-terminal-comm-server-tty-line-tacacs/m-p/4889639#M582969</guid>
      <dc:creator>stephanbrunst</dc:creator>
      <dc:date>2023-07-21T11:07:40Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Router as Terminal/Comm Server - TTY Line TACACS Authenticat</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-router-as-terminal-comm-server-tty-line-tacacs/m-p/4890224#M582994</link>
      <description>&lt;P&gt;I will check in my lab&lt;/P&gt;</description>
      <pubDate>Sat, 22 Jul 2023 22:16:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-router-as-terminal-comm-server-tty-line-tacacs/m-p/4890224#M582994</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2023-07-22T22:16:28Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Router as Terminal/Comm Server - TTY Line TACACS Authenticat</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-router-as-terminal-comm-server-tty-line-tacacs/m-p/4890508#M582996</link>
      <description>&lt;P&gt;Many thanks for your help. I'm looking forward to your feedback&lt;/P&gt;</description>
      <pubDate>Sun, 23 Jul 2023 18:21:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-router-as-terminal-comm-server-tty-line-tacacs/m-p/4890508#M582996</guid>
      <dc:creator>stephanbrunst</dc:creator>
      <dc:date>2023-07-23T18:21:21Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Router as Terminal/Comm Server - TTY Line TACACS Authenticat</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-router-as-terminal-comm-server-tty-line-tacacs/m-p/4890946#M583001</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot (983).png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/192346iC5956DA0B2AEBA19/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot (983).png" alt="Screenshot (983).png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.geeksforgeeks.org/difference-between-tacacs-and-radius/" target="_blank"&gt;Difference between TACACS+ and RADIUS - GeeksforGeeks&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;All the AAA packets are encrypted in TACACS+ &amp;lt;&amp;lt;- the packet is encrypted in tacacs that why we can not see password&amp;nbsp;or username&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 24 Jul 2023 10:05:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-router-as-terminal-comm-server-tty-line-tacacs/m-p/4890946#M583001</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2023-07-24T10:05:23Z</dc:date>
    </item>
  </channel>
</rss>

