Specifications

Chapter 12: Remote Authentication
205
About TACACS+ and CC-SG
CC-SG users who are remotely authenticated by a TACACS+ server
must be created on the TACACS+ server and on CC-SG. The user name
on the TACACS+ server and on CC-SG must be the same, although the
passwords may be different. See Users and User Groups (on page
156).
Add a TACACS+ Module
To add a TACACS+ module:
1. Choose Administration > Security.
2. Click the Authentication tab.
3. Click Add to open the Add Module window.
4. Choose Module Type > TACACS+.
5. Type a name for the TACACS+ server in the Module name field.
6. Click Next. The General tab opens.
TACACS+ General Settings
1. Type the IP address or hostname of the TACACS+ server in the IP
Address/Hostname Name field. See Terminology/Acronyms (on
page 2) for hostname rules.
2. Type the port number on which the TACACS+ server is listening in
the Port Number field. The default port number is 49.
3. Type the authentication port in the Authentication Port field.
4. Type the shared key in the Shared Key and Shared key confirm
fields. Maximum length is 128 characters.
5. Click OK to save your changes. The new TACACS+ module appears
in the Security Manager screen under External AA Servers.
6. Select the Authentication checkbox if you want CC-SG to use the
TACACS+ module for authentication of users.
7. Click Update to save your changes.