TACACS+ authorization feature provides authorization to access Sensor CLI by matching the service name in the TACACS server with the service name on the Sensor.The Sensor CLI access is given only when there is a matching service name.
The TACACS+ user is allowed to log into the Sensor CLI using his credentials and the session is created using a unique Sensor generated UID, whether authorization is enabled or disabled. Any local database file created for TACACS+ users at the Sensor is not persisted; after reboot, the database entries are created as and when the TACACS+ users login.
The audit log has all the operations performed by the TACACS+ user tagged to the user name.
The set tacacsauthorization command is used to set the TACACS+ authorization feature.
Syntax:
set tacacsauthorization <enable|disable>
Parameter | Description |
|---|---|
<enable> | Enables the TACACS+ authorization feature |
<disable> | Disables the TACACS+ authorization feature |
Default Value:
Disable
Applicable to:
NS-series Sensors