Add TACACS+ Profile
Focus
Focus
Prisma SD-WAN

Add TACACS+ Profile

Table of Contents

Add TACACS+ Profile

Learn how to add a TACACS+ profile.
Where Can I Use This?What Do I Need?
  • Prisma SD-WAN
  • Active Prisma SD-WAN license
A TACACS+ profile consists of up to four configured TACACS+ servers. If the first server isn't reachable, the system will sequentially try to connect to the other servers in the profile.
  1. Navigate to ManageResourcesConfiguration ProfilesAAA.
  2. Create a TACACS+ Profile.
  3. Enter profile Name and optionally Description and Tags.
  4. Select a Protocol from the available options CHA or PAP.
  5. Select Server Address Input- IPv4/IPv6 or FQDN.
  6. Enter the Server details, such as IP address, port, secret key, and server response time of a maximum of 10 seconds.
    If a user is present in the TACACS+ server and enters the correct credentials, the user will be able to log in successfully. If a user is present in both TACACS+ and local database, AAA server authentication is used. If a device isn't online, but the AAA server is reachable and the user is in the TACACS+ database, the user can log in using an SSH/remote connection.
    Local authentication (not TACACS+) is used when:
    • All four AAA servers are not reachable.
    • The user menu for offline device access.
    • The user isn't present in the TACACS+ server or database.
    • AAA servers are reachable but the user is present only in the local database.
    After creating the profile, associate a TACACS+ profile with a device. You can edit or delete a profile from the system.

Associate a TACACS+ Profile with a Device

After creating a profile, associate the profile with a device.
  1. Navigate to ManageSetupDevices.
  2. Select the device and then select the AAA configuration.
  3. Create TACACS+ Element Configuration for the selected device.
  4. Select the TACACS+ Profile and then select the Source Interface.
  5. Enter profile Name, Description, and Tags.
  6. If you want to customize the profile values, select Customize profile values.
  7. Customize the server and protocol values; when editing the values for the first time, you need to reenter the values and Submit.
    You can view the profile custom values on the TACACS+ page of the AAA tab. You can edit or delete the customized server details.