Skip to main content
FortiKoala
Staff
Staff
September 28, 2018

Technical Tip: TACACS+ Configuration

  • September 28, 2018
  • 0 replies
  • 3606 views

Description

 
This article describes how to configure Network Sentry to work in a TACACS+ environment.
 
Scope
 
FortiNAC.


Solution

  1. All switch models in Network Sentry have to be configured with a Super User and Password.
  2. The enable password has to be removed in all switch models in Network Sentry.
  3. The switches have to be configured so that the Super User gets dropped into the enable mode without an enable password.  


If global configuration is used, then:

 

  1. Fully test on one switch prior to doing mass implementation.
  2. Do a database backup on Network Sentry prior to the change so that a restore of the database will restore all switches to the previous configuration.
  3. Use the global configuration to push Username and Password changes. 
  4. Have a back out script that can run on all hardware switches to reverse password configuration changes and TACACS+ configuration if needed.