Adding clients
TACACS+ clients can be managed from Authentication > TACACS+ Service > Clients.
TACACS+ clients must use single-connection mode when using FortiAuthenticator for TACACS+ AAA |
Once created, clients can be assigned to a TACACS+ policy. See Creating policies.
To configure a TACACS+ client:
- Go to Authentication > TACACS+ Service > Clients, and click Create New to add a new TACACS+ client.
The Create New TACACS+ Client window opens. - Enter the following information:
Name Input a name to identify the TACACS+ client. Client address
Choose to specify the client address as an IP address or Subnet.
IP Address/Subnet Enter the IP address or subnet of the client. Secret Enter the TACACS+ passphrase that is shared with the client. - Select OK to add the new TACACS+ client.
If authentication fails, check that the authentication client is configured and that its IP address is correctly specified. Common causes of authentication problems are:
|
TACACS+ on FortiAuthenticator supports the ASCII authentication type. Other authentication types supported by the TACACS+ protocol (PAP, CHAP, and MSCHAPv2) will be denied. When configuring TACACS+ settings on a client, for example FortiGate, the ASCII authentication type must be selected. |