TACACS+

An AAA protocol over TCP that handles authentication, authorisation and accounting as separate exchanges, commonly used to control administrator access to network devices.

TACACS+ (Terminal Access Controller Access-Control System Plus) carries authentication, authorisation and accounting between a network device, acting as the client, and a central server. It runs over TCP and treats the three functions as separate exchanges, which lets the server authorise individual commands an administrator enters and record each one. RFC 8907 (2020) documents the protocol as deployed and describes its main use as device administration: who can sign in to routers, switches and firewalls, and what they may do there.

It is most often contrasted with RADIUS, which runs over UDP, returns authorisation inside the authentication response, and is commonly used for end-user network access, for example behind IEEE 802.1X. Study sources commonly add that RADIUS hides only the password while TACACS+ protects the whole packet body. RFC 8907 qualifies this: section 10.1 calls TACACS+‘s protection obfuscation rather than encryption, with no meaningful integrity, privacy or replay protection, so both protocols need a protected network or transport. Diameter is commonly described as the successor to RADIUS.

Exam relevance: a scenario about per-command authorisation and auditing for network administrators is likely to point to TACACS+, while end-user network access is likely to point to RADIUS. Candidates are expected to know the transport and the separation of the three functions, and to treat the whole-body protection as obfuscation.