Created on
07-02-2018
05:58 PM
Edited on
12-14-2025
02:05 PM
By
Jean-Philippe_P
Description
Scope
FortiAuthenticator.
Solution
Provides Authentication, Accounting, and Authorization for devices as routers, switches, firewalls, and servers. Uses TCP port 49, and the payload is encrypted, providing security.
Working:
Successful snippets of logs for reference.
TACACS+ Authentication logs:
2025-12-09T09:42:08.789839+00:00 FAC01 authen_tac_plus[2916]: 10.10.10.2 test1 ssh 10.10.10.1 pap login succeeded
2025-12-09T09:42:08.826070+00:00 FAC01 authen_tac_plus[44930]: 10.10.10.2 test1 ssh 10.10.10.1 pap login succeeded
TACACS+ Accounting logs:
2025-12-09T09:42:09.802826+00:00 FAC01 acct_tac_plus[2916]: 10.10.10.2 test1 ssh 10.10.10.1 start start_time=1215575841 task_id=64612 service=test-ssh protocol=ip
TACACS+ Authorization logs:
2025-12-09T09:42:08.523056+00:00 FAC01 author_tac_plus[60848]: 10.10.10.2 new.user/TestRule ssh 10.10.10.1 add test-ssh group1=global-read-write shell=/usr/bin/cli
Troubleshooting Commands:
Related articles:
FortiAuthenticator can be used as a TACACS+ server for Cisco Switch. Refer to Technical Tip: FortiAuthenticator as TACACS+ server for Cisco switch and clear pass for remote user ....
FortiAuthenticator can be used as a TACACS server, and FortiGate as the TACACS+ client. Refer to Technical Tip: Configure FortiAuthenticator as TACACS+ server, and FortiGate as TACACS+ client for a...
FortiAuthenticator is used as the TACACS+ server with FortiAnalyzer/FortiManager. Refer to Technical Tip: FortiAuthenticator as TACACS+ server for FortiAnalyzer / FortiManager user authorizat...
FortiAuthenticator is used as the TACACS+ server with steps for user authorization. Refer to Technical Tip: FortiAuthenticator as TACACS+ server for FortiGate user authorization.
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.