cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1059
Views
0
Helpful
6
Replies

TACACS+ to authenticate and authorize end Users in a network

orimbatomeizi
Level 1
Level 1

Hello

I just want to ask if there are any alternatives to 802.1x or web based authentication and authorization with TACACS+ only.

I can not use RADIUS although i have to authenticate end users with TACACS+ to allow them to use the network services like internet, mail, etc... As far i see TACACS+ is for device admnistration only but i was told that it can authenticate end users two instead of radius.

 

Thank you

6 Replies 6

balaji.bandi
Hall of Fame
Hall of Fame

If you like user to authenticate get to internet and allow to access internal resources.

 

as per i know you have only option 802.1x  deployment. (this can be done using Wired and Wireless)

 

https://www.cisco.com/c/en/us/td/docs/solutions/Enterprise/Security/TrustSec_1-99/Dot1X_Deployment/Dot1x_Dep_Guide.html

 

not sure how is your network what network devices you have in place to explore any other option, most time AAA is the only method.

 

 

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

Thank you for your answer... It is for research purposes for my network class project. I'm stuck with Tacacs+

 

 

 


Thank you

Hi

 They are basically the same.  The idea is the same, validate users against some user database and permit access or deny access. 

 

TACACS+                                                                                     RADIUS
Cisco proprietary protocol                                                            open standard protocol
It uses TCP as a transmission protocol                                          It uses UDP as a transmission protocol
It uses TCP port number 49.                                                        It uses UDP port number 1812 for authentication and authorization and 1813 for accounting.
Authentication, Authorization, and Accounting are separated        in TACACS+. Authentication and Authorization are combined in RADIUS.
All the AAA packets are encrypted. Only the password is encrypted while the

Thanks...

But tacacs+ is not 802.1x capable or web based authentication, based on what i see

Review Cisco Networking for a $25 gift card