cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
631
Views
0
Helpful
3
Replies

Can I intergrate TACACS+ authentication with MS AD?

qdsmisnet
Level 1
Level 1

hi, I would like to using MS AD account as a tacacs authentication account. I use tac_plus-F4.0.4.7 on Freebsd. Does anyone get some ideas? thank you!

3 Replies 3

pkapoor
Level 3
Level 3

I do not know if this would be the right place to ask a FreeBSD question. However, I do know that you can configure TACACS+ to refer to the AD database and authenticate users off that. My TACACS+ server is Cisco Secure ACS.

paul.mancuso
Level 1
Level 1

Although that is an interesting thought, I am also not up on that software and not sure this would be the best place to get that answer. For Cisco's Secure ACS, it is merely a click of the button. ACS from Cisco has many other features that I do know are not availabe in the few open source TACACS+ servers i have seen. I see no advantage even for small companies going this route given that the savings in dollars is little compared to the loss in functionality and interoperability among Cisco's products.

colin
Level 1
Level 1

Theoretically, you could do this with PAMs (Pluggable Authentication Modules), but at the end of the day, it's a lot of work to make it go.

I, like the other guys here, much prefer CiscoSecure ACS where it's just a click of a button.

It's also supported, whereas tac_plus is not.

Cheers,

-colin.