Authentication in TACACS+

TACACS+ authentication takes place via three distinct packet exchanges between the NAS and the TACACS+ daemon. TACACS+ authentication uses the following three types of packets:

  • START

  • REPLY

  • CONTINUE

Authentication starts when the NAS receives a connection request that needs to be authenticated. The NAS at this point sends a START message to the TACACS+ server. This message contains information regarding the type of authentication to be performed. It can also contain further information, such as the username and password. In answering the START message, the server responds with a REPLY message. If the server needs further information from the NAS to continue the authentication process, such as the password or other parameters ...

Get Network Security Principles and Practices now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.