
72 BSGX4e Business Gateway User Guide
NN47928-102 Release 01.01
One external authentication method uses the TACACS+ protocol. This protocol
provides authentication, authorization, and accounting services. Normal operation
fully encrypts the body of the packet for secure communication. It uses TCP port 49.
The TACACS+ client:
Is compatible with standard TACACS+ servers.
Maps TACACS+ authentication records to users by their user account name.
Can reference up to twenty TACACS+ authentication records.
Provides legacy authentication, enabling the BSGX4e to function as a Network
Access Server (NAS).
Configuration Steps
To configure a user account to use TACACS+ authentication, perform these steps:
1. Change the authentication (auth) value for the user account to TACACS+. This
value can be specified for the user account or for a user group to which the user
account belongs. (User account configuration is described in “User Accounts”
(page 61) and user group configuration is described in “User Groups” (page 64).)
2. Configure a TACACS+ authentication record for the user account.
NOTE: Disabling its authentication record suspends TACACS+ authentication
for a user account. This prevents logins by the user account until either
its authentication record is re-enabled or its authentication method
(auth) is changed.
TACACS+ Authentication Records
After a user account is configured to use TACACS+ authentication, a TACACS+
authentication record must be configured for that user account.
NOTE: The user account must be configured before the corresponding TACACS+
authentication record is configured (see “User Accounts” (page 61)).
Each user account that is to use TACACS+ password authentication must have its own
TACACS+ authentication record. If the same TACACS+ server is referenced by every
user account, the same values are specified in every authentication record.
The TACACS+ authentication record specifies:
the name or address of the TACACS+ server (server).
the key that the client shares with the server (key).
To configure a TACACS+ authentication record, enter the command:
> config tacplus client
Table 19 describes the parameters for config tacplus client.