<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: is it possible to Use TACACS authentication? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/is-it-possible-to-use-tacacs-authentication/m-p/45619#M33518</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Gururaj,&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;As per my knowledgeTACACS is not supported for authentication by PANFW as of now.&amp;nbsp; You can not use tricks, such as changing the port number to 49 instead of 1812 on RADIUS, because message format is different for both RADIUS and TACACS.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;RADIUS encrypts only the password in the access-request packet, from the client to the server. The remainder of the packet is unencrypted. Other information, such as username, authorized services, and accounting, can be captured by a third party.&lt;/P&gt;&lt;P&gt;&lt;IMG alt="Radius.JPG.jpg" class="jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/8048_Radius.JPG.jpg" /&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="TACACS.JPG.jpg" class="jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/8049_TACACS.JPG.jpg" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;TACACS+ encrypts the entire body of the packet but leaves a standard TACACS+ header. Within the header is a field that indicates whether the body is encrypted or not. For debugging purposes, it is useful to have the body of the packets unencrypted. However, during normal operation, the body of the packet is fully encrypted for more secure communications.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 04 Sep 2013 05:48:18 GMT</pubDate>
    <dc:creator>HULK</dc:creator>
    <dc:date>2013-09-04T05:48:18Z</dc:date>
    <item>
      <title>is it possible to Use TACACS authentication?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/is-it-possible-to-use-tacacs-authentication/m-p/45618#M33517</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there any tricks to use TACACS authentication? as PaloAlto dos't support TACACS auth directly.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Gururaj&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 04 Sep 2013 04:52:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/is-it-possible-to-use-tacacs-authentication/m-p/45618#M33517</guid>
      <dc:creator>Gururaj</dc:creator>
      <dc:date>2013-09-04T04:52:48Z</dc:date>
    </item>
    <item>
      <title>Re: is it possible to Use TACACS authentication?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/is-it-possible-to-use-tacacs-authentication/m-p/45619#M33518</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Gururaj,&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;As per my knowledgeTACACS is not supported for authentication by PANFW as of now.&amp;nbsp; You can not use tricks, such as changing the port number to 49 instead of 1812 on RADIUS, because message format is different for both RADIUS and TACACS.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;RADIUS encrypts only the password in the access-request packet, from the client to the server. The remainder of the packet is unencrypted. Other information, such as username, authorized services, and accounting, can be captured by a third party.&lt;/P&gt;&lt;P&gt;&lt;IMG alt="Radius.JPG.jpg" class="jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/8048_Radius.JPG.jpg" /&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="TACACS.JPG.jpg" class="jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/8049_TACACS.JPG.jpg" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;TACACS+ encrypts the entire body of the packet but leaves a standard TACACS+ header. Within the header is a field that indicates whether the body is encrypted or not. For debugging purposes, it is useful to have the body of the packets unencrypted. However, during normal operation, the body of the packet is fully encrypted for more secure communications.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 04 Sep 2013 05:48:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/is-it-possible-to-use-tacacs-authentication/m-p/45619#M33518</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2013-09-04T05:48:18Z</dc:date>
    </item>
    <item>
      <title>Re: is it possible to Use TACACS authentication?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/is-it-possible-to-use-tacacs-authentication/m-p/45620#M33519</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;As per my knowledge TACAS+ is currently no supported.&lt;/P&gt;&lt;P&gt;Currently the authentication for the users can be done based on Radius, LDAP and kerberos.&lt;/P&gt;&lt;P&gt;However if this is something that will be useful in your environment you can ask your Sales Engineer to file a feature request on your behalf.&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;&lt;P&gt;Numan &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 04 Sep 2013 15:23:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/is-it-possible-to-use-tacacs-authentication/m-p/45620#M33519</guid>
      <dc:creator>mbutt</dc:creator>
      <dc:date>2013-09-04T15:23:16Z</dc:date>
    </item>
    <item>
      <title>Re: is it possible to Use TACACS authentication?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/is-it-possible-to-use-tacacs-authentication/m-p/45621#M33520</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;There is a guide to authenticate PA to the Cisco ACS using RADIUS settings.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-1979"&gt;Configuring Cisco ACS 5.2 for use with Palo Alto VSA&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 04 Sep 2013 15:56:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/is-it-possible-to-use-tacacs-authentication/m-p/45621#M33520</guid>
      <dc:creator>pulukas</dc:creator>
      <dc:date>2013-09-04T15:56:52Z</dc:date>
    </item>
  </channel>
</rss>

