Adding clients
TACACS+ accounting clients can be managed from Authentication > TACACS+ Service > Clients.
Once created, clients can be assigned to a TACACS+ policy. See Creating policies.
To configure a TACACS+ client:
- Go to Authentication > TACACS+ Service > Clients, and click Create New to add a new TACACS+ client.
The Create New TACACS+ Client window opens. - Enter the following information:
Name Input a name to identify the TACACS+ client. Client address
Choose to specify the client address as a IP/Hostname or Subnet.
Name/IP Enter the FQDN/IP address or subnet of the client. Secret Enter the TACACS+ passphrase that is shared with the client. - Select OK to add the new TACACS+ client.
If authentication fails, check that the authentication client is configured and that its IP address is correctly specified. Common causes of authentication problems are:
|
TACACS+ on FortiAuthenticator supports the ASCII authentication type. Other authentication types supported by the TACACS+ protocol (PAP, CHAP, and MSCHAPv2) will be denied. When configuring TACACS+ settings on a client, for example FortiGate, the ASCII authentication type must be selected. |