TACACS+ Integration

Terminal Access Controller Access-Control System Plus (TACACS+) is a supported protocol for external authentication and authorization in A10 Control. TACACS+ server integration allows A10 Control delegate both authentication and authorization externally. The TACACS+ server validates user credentials, applies role-based authorization, and enforces access policies.

Only Organization Admins have permission to integrate the TACACS+ server with A10 Control.

Prerequisites

Before integrating TACACS+ server with A10 Control, ensure the following:

Configure TACACS+ Server for A10 Control Integration

  1. Set up and configure the TACACS+ server. For more information, see TACACS+ official documentation.
  2. Update the TACACS+ configuration file (/etc/tac_plus.conf) with the following details:

    • Listening port and shared secret (typically defined at the beginning of the file).
    • User accounts and their associated access group attributes.
  3. Restart the TACACS+ service after saving the configuration changes.

Verify and Test TACACS+ Integration

  1. Ask a TACACS+ server user to log in to the A10 Control portal with correct credentials.
  2. Verify the user is redirected to the TACACS+ server for authentication.
  3. If MFA is enabled, confirm that a second-factor challenge is presented.
  4. After successful login, verify that the user is assigned the correct role by checking either of the following:
    • A10 Control home page > Profile icon > User Profile.
    • A10 Control home page > Organization > Users > Users tab, where the External User column is marked as Yes.

COMPANY INFORMATION: Copyright © 2025 A10 Networks, Inc. All Rights Reserved. Legal Notice