10.4 Administrative Access Control: RADIUS vs TACACS+

Key Takeaways

  • RADIUS combines authentication and authorization in one Access-Accept, whereas TACACS+ (RFC 8907) separates authentication, authorization, and accounting into independent transactions.

  • TACACS+ provides full payload encryption (encrypting all fields after the 12-byte header), whereas RADIUS encrypts only the user password attribute within an otherwise cleartext UDP datagram.

  • TACACS+ operates over connection-oriented TCP port 49, ensuring immediate detection of server outages, whereas RADIUS relies on connectionless UDP ports 1812 and 1813.

  • The defining operational capability of TACACS+ is per-command authorization, enabling policy servers like ClearPass to inspect, permit, or deny individual CLI commands entered during an active administrative session.

  • When configuring AOS-CX administrative AAA, administrators must configure 'local' fallback following remote server groups to prevent total management lockout in the event of an authentication infrastructure outage.

Last updated: October 2026

Administrative Access Control: RADIUS vs TACACS+

Quick Summary: Campus network security extends beyond user access control to encompass management plane administration—securing CLI, SSH, Web UI, and REST API access to network switches. While RADIUS is widely deployed for network access control (802.1X), TACACS+ is the industry standard for device administration. TACACS+ decouples Authentication, Authorization, and Accounting into separate transactions, operates over reliable TCP port 49, encrypts the entire packet body, and uniquely supports granular per-command authorization. Configuring administrative AAA on AOS-CX requires defining server groups, enabling command authorization policies, and enforcing local fallback to prevent administrative lockouts during server outages.


Securing the Campus Management Plane

Enterprise network switches operate across three conceptual planes:

  • Data Plane: Forwards user frames and packets in hardware ASICs.
  • Control Plane: Maintains routing tables and spanning tree topologies (OSPF, BGP, MSTP).
  • Management Plane: Encompasses administrative management access methods, including SSH, switch console ports, the Web GUI, SNMP, and REST APIs.

The Vulnerability of Local Shared Credentials

In unmanaged environments, administrators frequently share a single static admin password. This practice introduces severe organizational and security risks:

  • Zero Accountability: Audit logs show actions executed by admin, making it impossible to determine which specific engineer executed a configuration change or caused an outage.
  • Revocation Bottlenecks: When an engineer departs an organization, the shared password must be manually updated across hundreds of switches.
  • Compliance Non-Compliance: Regulations (PCI-DSS, HIPAA, SOX, ISO 27001) mandate individual accountability and multi-factor or centralized administrative access control.

Centralized management access solves this by authenticating administrators against enterprise directories (such as Active Directory) through centralized AAA protocols.


Architectural Comparison: RADIUS vs. TACACS+

Two protocols dominate centralized AAA: RADIUS (Remote Authentication Dial-In User Service, RFC 2865/2866) and TACACS+ (Terminal Access Controller Access-Control System Plus, RFC 8907):

+---------------------------------------------------------------------------------------------------------+
|                                      RADIUS VS. TACACS+ ARCHITECTURE                                    |
|                                                                                                         |
|     [ RADIUS PROTOCOL ]                                                                                 |
|     - Purpose: Network Access Control (802.1X, VPNs, Wireless)                                          |
|     - AAA Structure: COMBINES Authentication & Authorization into one Access-Accept frame.             |
|     - Transport: Connectionless UDP (Ports 1812 Auth/AuthZ, 1813 Acct)                                  |
|     - Encryption: PARTIAL (Only the password attribute is encrypted; username and payload are visible)  |
|     - Authorization: Coarse-grained (Assigns a single privilege level upon initial login)                |
|                                                                                                         |
|     [ TACACS+ PROTOCOL ]                                                                                |
|     - Purpose: Network Device Administration (Routers, Switches, Firewalls)                             |
|     - AAA Structure: DECOUPLES Authentication, Authorization, and Accounting into separate phases.      |
|     - Transport: Connection-Oriented TCP (Port 49)                                                      |
|     - Encryption: FULL PAYLOAD (Entire packet encrypted after 12-byte header)                           |
|     - Authorization: FINE-GRAINED (Per-command authorization evaluated in real-time)                    |
+---------------------------------------------------------------------------------------------------------+

1. AAA Decoupling

  • RADIUS: Tightly couples Authentication and Authorization. When a user submits credentials, the server returns either an Access-Reject or an Access-Accept. All authorization metadata (such as privilege level or user role) must be bundled directly inside the Access-Accept packet. Once authenticated, no further authorization queries occur during that session.
  • TACACS+: Strictly separates all three services into independent protocol transactions:
    • An administrator can authenticate via one mechanism (e.g., Active Directory / Kerberos).
    • Authorization requests occur continuously throughout the active session.
    • Accounting runs as an entirely separate stream of TCP transactions.

2. Transport Protocol and Reliability

  • RADIUS: Runs over UDP (standard ports 1812 for authentication/authorization and 1813 for accounting; legacy ports 1645 and 1646). Because UDP is connectionless, the switch must implement application-layer timers and retransmission logic. Detecting a dead RADIUS server requires waiting for multiple request timeouts.
  • TACACS+: Runs over TCP port 49. The switch establishes a connection-oriented three-way handshake with the server. If the server crashes or the link drops, the switch receives an immediate TCP RST or detects connection termination within milliseconds, rapidly failing over to a secondary AAA server.

3. Packet Encryption Scope

  • RADIUS: Provides partial encryption. RADIUS encrypts only the User-Password attribute using a shared secret and an MD5 hash. The packet header, username, IP addresses, vendor-specific attributes, and all accounting information traverse the network in plaintext. An attacker capturing packets on intermediate links can harvest administrative usernames and monitor network activity.
  • TACACS+: Enforces full payload encryption. Only the standard 12-byte TACACS+ header remains in the clear (identifying sequence number, flags, and session ID). The entire body of the packet—including usernames, challenge prompts, authorized command strings, and configuration payloads—is cryptographically encrypted using an MD5-based stream cipher seeded by the shared secret.

Per-Command Authorization in TACACS+

The single most critical functional differentiator between RADIUS and TACACS+ in campus switch management is per-command authorization.

Why RADIUS Cannot Authorize Commands

Under RADIUS, authorization occurs once at login. ClearPass returns a privilege or role attribute (for example, an administrator or read-only role). Once the administrator enters the CLI, the switch evaluates permissions locally based on that static privilege level. The switch cannot query ClearPass dynamically to determine whether the user is permitted to run specific commands.

How TACACS+ Command Authorization Operates

TACACS+ enables real-time, interactive command filtering. Every time the administrator types a command and presses <Enter>, the switch suspends execution and queries ClearPass:

+---------------------------------------------------------------------------------------------------------+
|                                  TACACS+ PER-COMMAND AUTHORIZATION FLOW                                 |
|                                                                                                         |
|     [ Network Administrator ]             [ AOS-CX Switch ]                 [ ClearPass Policy Mgr ]    |
|                |                                  |                                     |               |
|                | --- Types: "show vlan" --------> |                                     |               |
|                |                                  | --- TACACS+ AuthZ Request --------> |               |
|                |                                  |     User: j_doe, Cmd: "show vlan"   |               |
|                |                                  |                                     +-- Matches     |
|                |                                  | <--- TACACS+ AuthZ PASS ------------+   Permit Set  |
|                | <=== Outputs VLAN Table ======== |                                     |               |
|                |                                  |                                     |               |
|                | --- Types: "erase startup" ----> |                                     |               |
|                |                                  | --- TACACS+ AuthZ Request --------> |               |
|                |                                  |     User: j_doe, Cmd: "erase ..."   |               |
|                |                                  |                                     +-- Matches     |
|                |                                  | <--- TACACS+ AuthZ FAIL ------------+   Deny Rule   |
|                | <=== "% Command Denied!" ======= |                                     |               |
+---------------------------------------------------------------------------------------------------------+
  1. Command Interception: The administrator enters interface 1/1/1 and presses Enter. The switch CLI engine intercepts the command string.
  2. Authorization Request: The switch generates a TACACS+ AUTHOR_REQUEST packet containing:
    • user: j_doe
    • cmd: interface
    • cmd-arg: 1/1/1
  3. Policy Evaluation on ClearPass: ClearPass checks the user's role against configured TACACS+ Command Sets:
    • Tier-1 Helpdesk: Permitted commands: show *, ping *, traceroute *. Denied: configure *, erase *.
    • Senior Network Engineers: Permitted commands: * (unrestricted).
  4. Execution Decision: ClearPass responds with TACACS_AUTHOR_STATUS_PASS_ADD or STATUS_FAIL. If permitted, the switch executes the command; if denied, the switch displays % Command authorization failed and logs an accounting alert.

Technical Comparison: RADIUS vs. TACACS+

Technical DimensionRADIUS (RFC 2865 / 2866)TACACS+ (RFC 8907)
Primary Use CaseNetwork Access Control (802.1X, VPNs, Wi-Fi)Device Administration (CLI, SSH, Switch Web UI)
AAA ArchitectureCombined Authentication and AuthorizationStrictly Decoupled (Independent AuthN, AuthZ, Acct)
Transport ProtocolUDP (Connectionless)TCP (Connection-Oriented)
Network PortsPort 1812 (Auth/AuthZ), Port 1813 (Acct)Port 49 (AuthN, AuthZ, Acct)
Encryption ScopePartial (User-Password attribute only)Full Payload (Entire body encrypted)
Command AuthorizationNo (Coarse privilege level at login only)Yes (Real-time per-command authorization)
Accounting ReliabilityBest-effort UDP retransmissionsReliable TCP delivery with acknowledgements
Challenge-ResponseSupported (EAP)Supported (Interactive ASCII challenges)

AOS-CX Configuration for Administrative AAA

The following configuration illustrates defining TACACS+ servers, creating server groups, configuring authentication and command authorization, and enforcing local fallback on an AOS-CX switch:

switch# configure terminal

! Step 1: Define Primary and Secondary TACACS+ Servers
switch(config)# tacacs-server host 10.10.100.50 key plaintext SecretTacacsKey123
switch(config)# tacacs-server host 10.10.100.51 key plaintext SecretTacacsKey123

! Step 2: Create a TACACS+ Server Group
switch(config)# aaa group server tacacs CPPM-TACACS-GROUP
switch(config-sg)# server 10.10.100.50
switch(config-sg)# server 10.10.100.51
switch(config-sg)# exit

! Step 3: Configure Administrative Login Authentication with Local Fallback
switch(config)# aaa authentication login default group CPPM-TACACS-GROUP local
switch(config)# aaa authentication login console group CPPM-TACACS-GROUP local

! Step 4: Configure Per-Command Authorization
switch(config)# aaa authorization commands default group CPPM-TACACS-GROUP local

! Step 5: Configure Administrative Command Accounting
switch(config)# aaa accounting all-mgmt default start-stop group CPPM-TACACS-GROUP

The Critical Role of Local Fallback and Lockout Prevention

Notice the authentication syntax: aaa authentication login default group CPPM-TACACS-GROUP local.

  • Order of Evaluation: The switch evaluates authentication methods from left to right. When an administrator initiates an SSH session, the switch queries the servers in CPPM-TACACS-GROUP first. If reachable, ClearPass handles the authentication.
  • The Fallback Trigger: The switch falls back to the local user database only if all remote TACACS+ servers are completely unreachable (connection timed out or TCP connection reset).
  • The Rejection Rule: If ClearPass is online and returns an Authentication Failure (e.g., the engineer entered the wrong password), the switch does not fall back to local by default. It rejects the login immediately. Fallback exists to survive infrastructure outages, not to provide an alternative path for bad passwords. (AOS-CX can be changed to fail through to the next method after a reject with aaa authentication allow-fail-through, which is not the default.)
  • Disastrous Misconfiguration: If an administrator omits local from the command (aaa authentication login default group CPPM-TACACS-GROUP) and an upstream firewall cuts off access to ClearPass, all administrators are completely locked out of the switch, requiring a physical console password-recovery reboot.

Common Exam Traps

  • TACACS+ Encryption Myth: A common exam question tests packet visibility. Candidates incorrectly assume RADIUS encrypts the packet body. RADIUS encrypts only the password. TACACS+ encrypts the entire payload.
  • Transport Port Confusion: Remembering that TACACS+ uses TCP port 49, whereas modern RADIUS uses UDP ports 1812 and 1813 (or legacy 1645/1646).
  • Local Fallback Behavior: Believing that entering an invalid password triggers local authentication fallback. By default, local fallback triggers only when the remote servers are unreachable or time out, not on an explicit authentication failure (unless aaa authentication allow-fail-through is configured).
Loading diagram...
RADIUS Combined AuthN/AuthZ vs. TACACS+ Decoupled Per-Command Authorization
Test Your Knowledge

A network security auditor reviews a campus access infrastructure and recommends migrating switch administrative management from RADIUS to TACACS+. Which technical capability uniquely provided by TACACS+ justifies this architectural transition?

A

TACACS+ combines authentication and authorization into a single transaction to reduce CPU overhead on switch control processors

B

TACACS+ supports dynamic VLAN assignment using 802.1Q encapsulated frames on access ports

C

TACACS+ operates over connectionless UDP datagrams to minimize latency during heavy administrative workloads

D

TACACS+ strictly decouples authentication from authorization, encrypts the entire packet body, and enables real-time per-command authorization

Test Your Knowledge

An administrator on an AOS-CX switch executes the command: 'switch(config)# aaa authentication login default group CPPM-TACACS-GROUP local'. What occurs when an engineer attempts to log into the switch via SSH while entering an incorrect password?

A

The switch immediately queries the local user database to check if the entered password matches the local admin account

B

The switch rejects the login attempt immediately because the TACACS+ server is reachable and returned an explicit authentication failure

C

The switch prompts the user to select an anonymous outer identity before terminating the SSH session

D

The switch establishes a secondary TCP session on port 1812 to query ClearPass using RADIUS authentication

Test Your Knowledge

Which network transport protocol and port configuration correctly identifies the communication channel utilized by TACACS+ for administrative access control?

A

TCP port 49

B

TCP port 1813

C

UDP port 1812

D

UDP port 49

Sections you finish are checked off in the contents.