This article explains the configuration statements required on the EX Series Ethernet Switch required for authentication and accounting with the Windows based Cisco ACS Server.
Authentication succeeds when using EX Series Switch with Windows based Cisco ACS server, however the accounting information does not get logged in the accounting log file on the Cisco ACS
Cisco ACS server can be used for TACACS+ Authentication and accounting with the EX series etherent switches. Terminal Access Controller Access Control System (TACACS) is a security protocol that provides centralized validation of users who are attempting to gain access to a switch/router or NAS. TACACS+, a more recent version of the original TACACS protocol, provides separate authentication, authorization, and accounting (AAA) services.Like RADIUS, TACACS+ uses a client/server model, with the switch being the client. All transactions between the server and the client are authenticated by a shared secret. The JUNOS configuration for TACACS+ is almost identical to that for RADIUS. You set the IP address of your TACACS+ server and the password (secret) that the EX switch should use to access the server. The secrets on the EX switch and the server must match. For more information on the Cisco ACS server you may refer to www.cisco.com. For detailed information on configuring RADIUS and authentication mechanisms on the EX you may refer to Knowledge base article KB15045 [juniper.net] and KB15046 [juniper.net]. A. Configuring the EX series switch to send TACACS+ Authentication requests to the Cisco ACS server.
NOTE: where <class> is a well defined login class with specific permissions on the EX. The defined classes with their permissions are: