11.2 AAA Architecture: Comparing RADIUS vs. TACACS+ and Method List Configuration
Key Takeaways
The AAA security architecture structures access control into three independent functions: Authentication ('Who are you?'), Authorization ('What can you do?'), and Accounting ('What did you do?').
TACACS+ (RFC 8907) operates over TCP port 49, separates authentication, authorization, and accounting into distinct transactions, and encrypts the entire packet payload, making it the preferred protocol for device administration and per-command authorization.
RADIUS (RFC 2865/2866) operates over UDP ports 1812/1813, combines authentication and authorization into a single response packet, and encrypts only the password attribute, making it ideal for network access control (802.1X, dot1x, VPNs, wireless).
AAA method lists evaluate authentication sources sequentially, but fallback to secondary methods (such as local credentials) occurs strictly when the primary server is unreachable or dead; an active authentication rejection from the server terminates the session immediately without fallback.
Production AAA configurations employ named server groups (aaa group server tacacs+), command authorization (aaa authorization commands 15), accounting start-stop logs, and targeted diagnostic debugging (debug tacacs, debug aaa authentication).
AAA Architecture: Comparing RADIUS vs. TACACS+ and Method List Configuration
In enterprise network infrastructures containing hundreds or thousands of routers, switches, and firewalls, maintaining local user accounts on individual devices is unscalable, operationally inefficient, and introduces severe security compliance risks. If an administrator resigns or changes roles, manually updating or removing accounts across thousands of devices is impractical. The Authentication, Authorization, and Accounting (AAA) framework resolves this challenge by centralizing identity management, access policy enforcement, and audit logging on dedicated security servers such as Cisco Identity Services Engine (ISE).
The AAA Architectural Framework
The AAA framework decouples identity and access control into three distinct functional components:
+-------------------------------------------------------------------------+
| The AAA Security Paradigm |
+-------------------------------------------------------------------------+
| 1. Authentication | "Who are you?" |
| | Validates user identity via credentials, tokens, |
| | or digital certificates. |
+---------------------+---------------------------------------------------+
| 2. Authorization | "What are you allowed to do?" |
| | Determines permitted services, privilege levels, |
| | and specific CLI commands per session. |
+---------------------+---------------------------------------------------+
| 3. Accounting | "What did you do, and for how long?" |
| | Records session start/stop times, executed |
| | commands, and resource utilization for audits. |
+---------------------+---------------------------------------------------+
When a network device is configured for AAA, it ceases to act as an isolated security island. Instead, the device functions as an AAA Client (or Network Access Server / NAS), intercepting user connection requests and forwarding transaction packets to centralized AAA Servers via standard protocols.
Protocol Deep-Dive: TACACS+ vs. RADIUS
Two primary protocols implement AAA services in enterprise networks: TACACS+ (Terminal Access Controller Access-Control System Plus) and RADIUS (Remote Authentication Dial-In User Service). Although both protocols provide centralized AAA capabilities, their internal architectures, transport mechanisms, and security profiles differ fundamentally.
TACACS+ Packet Architecture (TCP Port 49):
+------------------------+------------------------------------------------+
| 12-Byte Header (Clear) | Encrypted Entire Packet Payload |
| (Seq, Flags, SessionID)| (Username, Passwords, Attributes, CLI Commands)|
+------------------------+------------------------------------------------+
RADIUS Packet Architecture (UDP Port 1812/1813):
+------------------------+------------------------------------------------+
| Standard Header (Clear)| Unencrypted Body & Attributes |
| (Code, ID, Length) | (Username, AV-Pairs Clear; ONLY Password Enc.) |
+------------------------+------------------------------------------------+
TACACS+ (RFC 8907)
Originally developed by Cisco as an enhancement to legacy TACACS and XTACACS, TACACS+ is documented as an informational standard in RFC 8907. TACACS+ is designed specifically for device administration and management plane security:
- Transport Protocol: TACACS+ operates over connection-oriented TCP port 49. Because TCP establishes a reliable three-way handshake, devices immediately detect network disconnections, packet loss, or server unreachability.
- Full Payload Encryption: TACACS+ encrypts the entire body of the packet using a shared secret key and the MD5 cryptographic algorithm. Only the standard 12-byte header (which conveys session identifiers, sequence numbers, and flags) is transmitted in cleartext. Usernames, passwords, authorization attributes, and typed CLI commands remain completely shielded from network packet sniffers.
- Separation of AAA Services: TACACS+ strictly decouples Authentication, Authorization, and Accounting into distinct, independent socket transactions. A network device can perform authentication against an external LDAP/Active Directory identity store, execute granular per-command authorization against a centralized Cisco ISE policy engine, and stream accounting records to a third-party security information and event management (SIEM) platform.
- Per-Command Authorization: Because authorization operates independently, Cisco IOS XE can be configured to intercept every single CLI command an administrator types (
aaa authorization commands 15) and query the TACACS+ server in real-time before executing the command. If an operator attempts to runreloadorno router ospf 1, the device sends an authorization request packet containing the specific command string. The server permits or denies the command instantly based on the operator's group policy.
RADIUS (RFC 2865 / RFC 2866)
Standardized by the Internet Engineering Task Force (IETF) under RFC 2865 (Authentication and Authorization) and RFC 2866 (Accounting), RADIUS is an open, vendor-neutral standard designed primarily for network access control:
- Transport Protocol: RADIUS operates over connectionless UDP, utilizing ports 1812 for Authentication/Authorization and 1813 for Accounting. Older legacy implementations utilize UDP ports 1645 and 1646. Because UDP is stateless, RADIUS relies on application-layer retry timers and retransmission counters.
- Partial Encryption: RADIUS encrypts only the User-Password attribute inside the Access-Request packet using an MD5 hash combined with the shared secret. The remainder of the packet—including the username, client IP, accounting statistics, and authorization attributes—is transmitted in unencrypted plaintext across the transit network.
- Coupled Authentication and Authorization: RADIUS fundamentally binds Authentication and Authorization into a single transactional exchange. When a user submits credentials, the server evaluates identity and returns an
Access-AcceptorAccess-Rejectpacket. TheAccess-Acceptpacket bundles authorization parameters—such as assigned VLAN IDs, Access Control Lists (dACLs), and Cisco AV-Pairs—directly within the authentication response. RADIUS cannot authorize services independently of the initial authentication handshake. - Absence of Per-Command Authorization: Because RADIUS lacks a dedicated authorization channel, it cannot perform per-command CLI validation. RADIUS typically returns a static privilege level (e.g., Level 15) during login, granting the user broad command execution authority. Consequently, RADIUS is optimal for endpoint network access (such as 802.1X port authentication, wireless WPA2/WPA3-Enterprise, and remote-access VPN termination) rather than granular CLI device administration.
TACACS+ vs. RADIUS Architectural Comparison
| Architectural Attribute | TACACS+ (RFC 8907) | RADIUS (RFC 2865 / 2866) |
|---|---|---|
| Origin / Standards Body | Cisco Developed / Informational RFC 8907 | IETF Open Standard (RFC 2865 / 2866) |
| Transport Layer & Ports | TCP Port 49 (Connection-oriented, reliable) | UDP Ports 1812 (Auth) & 1813 (Acct) / Legacy 1645 & 1646 |
| Packet Encryption Scope | Entire packet payload encrypted; 12-byte header clear | Password attribute only encrypted; rest of packet clear |
| AAA Service Separation | Strictly separated into independent transactions | Authentication and Authorization coupled in single response |
| Command Authorization | Granular per-command authorization supported | Coarse; authorization restricted to initial login attributes |
| Accounting Capabilities | Extensive; captures detailed CLI command records | Standardized session duration and packet/byte counters |
| Primary Enterprise Use Case | Device Administration (Routers, Switches, Firewalls) | Network Access Control (802.1X, Wireless, VPN Clients) |
AAA Server and Server Group Provisioning
Cisco IOS XE modernizes AAA configuration by replacing legacy flat commands (tacacs-server host ...) with named server objects and server groups.
Server Object Definition
Administrators define individual server objects specifying IP addresses, ports, and pre-shared encryption keys:
! Defining TACACS+ Servers
tacacs server ISE-TACACS-PRIMARY
address ipv4 10.1.100.11
key 6 070C285F4D0648471A1D0A182E
timeout 5
tacacs server ISE-TACACS-SECONDARY
address ipv4 10.1.100.12
key 6 070C285F4D0648471A1D0A182E
timeout 5
Server Group Aggregation
Individual server definitions are aggregated into named server groups. Server groups enable high-availability clustering and allow administrators to reference logical server pools across multiple method lists:
aaa group server tacacs+ TACACS-CLUSTER
server name ISE-TACACS-PRIMARY
server name ISE-TACACS-SECONDARY
ip tacacs source-interface Loopback0
Configuring ip tacacs source-interface Loopback0 guarantees that all AAA control packets originate from a stable, non-flapping virtual interface, preventing firewall drop states during physical interface failover.
AAA Method Lists and Fallback Logic
A Method List defines the sequential sequence of authentication, authorization, or accounting methods that Cisco IOS XE queries when processing an administrative event.
Default vs. Named Method Lists
- Default Method Lists: Automatically apply to all lines (Console, Aux, VTY) and interfaces across the device unless a named method list is explicitly assigned. Configured using the keyword
default(e.g.,aaa authentication login default group TACACS-CLUSTER local). - Named Method Lists: Custom lists identified by a user-defined alphanumeric string. Named lists do not affect device behavior until explicitly bound to specific lines or interfaces using the
login authentication <list-name>command. Named lists allow administrators to enforce distinct security policies across different management vectors (e.g., applying strict TACACS+ policies to VTY lines while applying a dedicated local method list to the console).
Critical Fallback Mechanics: Server Unreachable vs. Server Reject
A foundational concept in AAA engineering is understanding the exact conditions under which Cisco IOS XE falls back to subsequent methods in a list:
User submits login credentials (username/password)
|
v
[ Query Primary Server in Method List ]
|
+------------+------------+
| |
v v
[Server Responds] [Server Does NOT Respond]
| (Timeout, Unreachable, Connection Reset)
| |
+-----+-----+ v
| | [ FALLBACK TO NEXT METHOD ]
v v (e.g., Local Database)
[ACCEPT] [REJECT] |
| | +-----+-----+
| v | |
Success TERMINATE v v
SESSION! [MATCH] [NO MATCH]
(NO Fallback!) | |
v v
Success Access Denied
- Server Unreachable / Timeout (FALLBACK OCCURS): If the primary AAA server is offline, down for maintenance, or network routing issues prevent TCP connection establishment, the query timer expires. Cisco IOS XE detects that the server is unresponsive (DEAD) and immediately falls back to the next method in the list (such as a secondary server group or the
localdatabase). - Server Reject / Authentication Failure (NO FALLBACK): If the primary AAA server receives the packet, processes the request, and determines that the password is incorrect or the user account is disabled, the server returns an explicit REJECT response. Cisco IOS XE treats this as an authoritative security decision. The authentication attempt fails immediately, and the session is terminated. The router never falls back to subsequent methods when an active reject is received.
Caution
If an administrator misconfigures AAA and the central TACACS+ server actively rejects their credentials, local accounts configured on the router will not be evaluated. Local fallback occurs strictly when all external servers fail to respond.
AAA Method List Fallback Evaluation Matrix
| Method List Configuration | Primary Server Status | Credential Status | Device Operational Action | Resulting Outcome |
|---|---|---|---|---|
group TACACS local | Responding (UP) | Valid on TACACS+ | Server returns PASS; session established | Authenticated via TACACS+ |
group TACACS local | Responding (UP) | Invalid on TACACS+ | Server returns FAIL; login denied; local DB ignored | Access Denied immediately |
group TACACS local | Unreachable (DOWN) | Present in Local DB | TCP timeout expires; router falls back to local database | Authenticated via Local DB |
group TACACS local | Unreachable (DOWN) | Invalid in Local DB | TCP timeout expires; router falls back to local DB; credentials fail | Access Denied via Local DB |
group TACACS (No local) | Unreachable (DOWN) | Present in Local DB | TCP timeout expires; no fallback method defined in list | Lockout (Access Denied) |
Comprehensive AAA Hardening Configuration Walkthrough
The following configuration establishes a hardened AAA deployment on Cisco IOS XE, including server clusters, login authentication, command authorization, accounting records, and console safety overrides:
! Step 1: Initialize the AAA Framework
aaa new-model
! Step 2: Define External TACACS+ Servers
tacacs server ISE-NODE-01
address ipv4 10.1.100.21
key 6 070C285F4D0648471A1D0A182E
timeout 3
tacacs server ISE-NODE-02
address ipv4 10.1.100.22
key 6 070C285F4D0648471A1D0A182E
timeout 3
! Step 3: Group Servers into a Resilient Pool
aaa group server tacacs+ ISE-TACACS-POOL
server name ISE-NODE-01
server name ISE-NODE-02
ip tacacs source-interface Loopback0
! Step 4: Configure Authentication Method Lists
! Authenticate against TACACS+ pool; fall back to local database if servers are dead
aaa authentication login default group ISE-TACACS-POOL local
aaa authentication login CONSOLE-LOCAL local
aaa authentication enable default group ISE-TACACS-POOL enable
! Step 5: Configure Authorization Method Lists
! Authorize EXEC shell startup and enforce per-command Level 15 validation
aaa authorization exec default group ISE-TACACS-POOL local
aaa authorization commands 15 default group ISE-TACACS-POOL local
! Step 6: Configure Accounting Method Lists
! Stream start-stop audit records for all sessions and privilege 15 commands
aaa accounting exec default start-stop group ISE-TACACS-POOL
aaa accounting commands 15 default start-stop group ISE-TACACS-POOL
! Step 7: Apply AAA Policies to Access Lines
line con 0
exec-timeout 5 0
logging synchronous
! Console uses only the local database, so a TACACS+ outage or policy error cannot lock you out
login authentication CONSOLE-LOCAL
line vty 0 15
exec-timeout 5 0
logging synchronous
transport input ssh
transport output none
login authentication default
Verification and Operational Troubleshooting
When deploying or troubleshooting AAA architectures, network engineers rely on specific non-disruptive validation commands and targeted debug output.
Non-Disruptive Credential Testing (test aaa)
To verify that a newly configured server group or pre-shared key is functioning properly without logging out of the current session, administrators use the test aaa EXEC command:
Router# test aaa group ISE-TACACS-POOL netadmin MyPassword123! legacy
Attempting authentication test to server-group ISE-TACACS-POOL using tacacs+
User was successfully authenticated.
Checking Server Operational State
The show aaa servers command displays real-time statistics regarding server availability, socket state, response latencies, and transaction counters:
Router# show aaa servers
TACACS+ Platform Provider: Available
Server: ISE-NODE-01 (10.1.100.21:49) State: UP
Connection: Established, Total connections: 42
Messages: Sent 184, Received 184, Timeout 0
Estimated latency: 8 ms
Server: ISE-NODE-02 (10.1.100.22:49) State: UP
Connection: Idle, Total connections: 0
Messages: Sent 0, Received 0, Timeout 0
Targeted Diagnostic Debugging
When authentication or authorization failures occur, specific debug commands isolate the failure point:
debug aaa authentication: Displays real-time step-by-step traversal of authentication method lists, credential exchange transactions, and method transitions.debug aaa authorization: Tracks attributes passed during EXEC shell startup and displays the exact permit or deny response returned for each intercepted CLI command.debug aaa accounting: Displays generated accounting start, stop, and update records along with server delivery receipts.debug tacacs: Decodes raw TACACS+ protocol transactions, including TCP socket establishment, packet sequence synchronization, payload encryption/decryption flags, and error codes.debug radius: Decodes UDP datagram transmissions, RADIUS packet types (Access-Request,Access-Accept,Access-Reject), and individual Attribute-Value (AV) pair payloads.
A network administrator configures the command aaa authentication login default group TACACS-POOL local. During an administrative login attempt, the primary TACACS+ server actively responds with an authentication reject message due to an expired password. What action does the router take?
The router queries the local user database to evaluate the submitted credentials
The router prompts the administrator to enter the auxiliary line rescue password
The router terminates the session and denies access immediately without evaluating the local database
The router broadcasts an ARP discovery packet to locate an alternate TACACS+ server
Which architectural characteristic fundamentally differentiates TACACS+ from RADIUS when implementing management plane security?
TACACS+ encrypts the entire packet payload and decouples authentication, authorization, and accounting into independent transactions
TACACS+ operates over connectionless UDP port 49 to maximize throughput for per-command authorization checks
TACACS+ bundles authentication and authorization into a single response packet to minimize WAN round-trip latency
TACACS+ encrypts only the user password attribute while transmitting typed CLI commands in cleartext
A network compliance auditor requires that all Privileged EXEC commands executed by engineers on core infrastructure routers be logged with timestamps to an external server. Which AAA command fulfills this requirement?
aaa authorization commands 15 default group TACACS-POOL none
aaa accounting network default start-stop group TACACS-POOL
aaa authentication login default group TACACS-POOL local
aaa accounting commands 15 default start-stop group TACACS-POOL
Sections you finish are checked off in the contents.