cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
834
Views
0
Helpful
3
Replies

Can a TACACS+ server query a RADIUS server?

tamyotte
Level 1
Level 1

Hi All.

My work environment currently uses FreeRADIUS for all of our customer and staff AAA requirements.  This currently includes access to all of our Cisco devices.

My boss now wants to set up a TACACS+ server for access to all our Cisco devices, but wants the TACACS+ server to query the RADIUS server and its database in turn.  In other words, he wants the TACACS+ server to act as a kind of proxy and relay the request to RADIUS, and to have RADIUS pass the accept or reject back to the TACACS+, and then back to the Cisco device.

Does anyone know if this is possible?  I'm pretty sure you can do this with 2 RADIUS servers...

3 Replies 3

What version of ACS?

Good question.  We do not currently have a TACACS+ server, and would have to build one if this is possibility.

Having said that, I believe my boss is just going to go for local authentication on the few switches where this is a problem.

I was assuming you were using ACS as your TACACS+ server. It can proxy to a RADIUS server. I don't know about other TACACS+ servers, though.