Fortinet black logo

Administration Guide

Adding clients

Adding clients

TACACS+ accounting clients can be managed from Authentication > TACACS+ Service > Clients.

Once created, clients can be assigned to a TACACS+ policy. See Creating policies.

To configure a TACACS+ client:
  1. Go to Authentication > TACACS+ Service > Clients, and click Create New to add a new TACACS+ client.
    The Create New TACACS+ Client window opens.
  2. Enter the following information:
    Name Input a name to identify the TACACS+ client.

    Client address

    Choose to specify the client address as a IP/Hostname or Subnet.

    Name/IP Enter the FQDN/IP address or subnet of the client.
    Secret Enter the TACACS+ passphrase that is shared with the client.
  3. Select OK to add the new TACACS+ client.
Tooltip

If authentication fails, check that the authentication client is configured and that its IP address is correctly specified. Common causes of authentication problems are:

  • TACACS+ packets sent from an unexpected interface, or IP address.
  • NAT performed between the authentication client and FortiAuthenticator.
Tooltip

TACACS+ on FortiAuthenticator supports the ASCII authentication type. Other authentication types supported by the TACACS+ protocol (PAP, CHAP, and MSCHAPv2) will be denied.

When configuring TACACS+ settings on a client, for example FortiGate, the ASCII authentication type must be selected.

Adding clients

TACACS+ accounting clients can be managed from Authentication > TACACS+ Service > Clients.

Once created, clients can be assigned to a TACACS+ policy. See Creating policies.

To configure a TACACS+ client:
  1. Go to Authentication > TACACS+ Service > Clients, and click Create New to add a new TACACS+ client.
    The Create New TACACS+ Client window opens.
  2. Enter the following information:
    Name Input a name to identify the TACACS+ client.

    Client address

    Choose to specify the client address as a IP/Hostname or Subnet.

    Name/IP Enter the FQDN/IP address or subnet of the client.
    Secret Enter the TACACS+ passphrase that is shared with the client.
  3. Select OK to add the new TACACS+ client.
Tooltip

If authentication fails, check that the authentication client is configured and that its IP address is correctly specified. Common causes of authentication problems are:

  • TACACS+ packets sent from an unexpected interface, or IP address.
  • NAT performed between the authentication client and FortiAuthenticator.
Tooltip

TACACS+ on FortiAuthenticator supports the ASCII authentication type. Other authentication types supported by the TACACS+ protocol (PAP, CHAP, and MSCHAPv2) will be denied.

When configuring TACACS+ settings on a client, for example FortiGate, the ASCII authentication type must be selected.