Configuring TACACS+ Authentication

1.Log in to the System Management page.

2.In the System Management page, click User Accounts > External Authentication.

3.Click the icon and select Add TACACS+ Authentication from the drop-down list.

Assign user role manually
Map user role from TACACS+ to NetBrain

4.In the pop-up dialog, enter the username and password of any existing user accounts on the TACACS+ server and click Verify to authenticate the connection.

Note: To prevent the assigned roles and privileges of an external user account from being synced with any changed authentication settings, you can lock the user rights as follows as soon as the user has logged in to the IE system. See Creating User Account for more details.

TACACS+ Server Settings

The following table lists the credentials that are required when connecting to a TACACS+ server.

Field

Description

Primary Server IP

The IP address of the primary TACACS+ server.

Secondary Server IP

The IP address of a backup TACACS+ server. It is used when the primary TACACS+ server is unavailable. If you do not have the backup server, leave this field empty.

Server Port

The port number used to listen for TACACS+ authentication requests and send responses. Make sure it is consistent with the port number you have configured on the TACACS+ server.

Secret Key

The password used to access the TACACS+ server. Make sure it is consistent with the key that you have configured on the TACACS+ server.

Login Mode

The authentication method used to encrypt the connections to the TACACS+ server. Four types of login modes are supported: Standard ASCII, PAP, CHAP, and MS-CHAP. Make sure it is consistent with the authentication method you have configured on the TACACS+ server.

Authentication Timeout

The time interval between sending authentication password and getting an authentication response from the TACACS+ server. When the authentication time exceeds the threshold, it will be treated as an authentication timeout and an error message will be displayed.