TACACS+ server recommendations?

Alberto Vargas avargasn at gmail.com
Fri Sep 22 20:46:21 UTC 2023


It seems they can do it: https://www.miniorange.com/iam/solutions/tacacs-authentication

From: NANOG <nanog-bounces+avargasn=gmail.com at nanog.org> on behalf of Tim Burke <tim at mid.net>
Date: Friday, 22 September 2023 17:32
To: North American Network Operators Group <nanog at nanog.org>, Kevin Burke <kburke at burlingtontelecom.com>
Subject: Re: TACACS+ server recommendations?

Curious about this as well.

We are using Okta's RADIUS service for 2fa to network gear currently, but looking to switch to tacacs+ for many reasons. Would prefer to implement tacacs+ with two-factor if possible.

________________________________
From: NANOG <nanog-bounces+tim=mid.net at nanog.org> on behalf of Kevin Burke via NANOG <nanog at nanog.org>
Sent: Friday, September 22, 2023 1:53 PM
To: North American Network Operators Group <nanog at nanog.org>
Subject: RE: TACACS+ server recommendations?

Is anyone using two factor authentication for network devices?

Getting ready to re-do our authentication infrastructure and was curious if this is common.  We are noticing a lot of Active Directory based two factor solutions as well as some TACACS solutions that have already been mentioned that can use AD as the backend.  Also curious if others have tried this and noticed any obvious downsides.

Thanks!

Kevin Burke
802-540-0979
Burlington Telecom
200 Church St, Burlington, VT
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://mailman.nanog.org/pipermail/nanog/attachments/20230922/605e44a9/attachment.html>


More information about the NANOG mailing list