TACACS+
- Last Updated: April 5, 2026
- 2 minute read
- Flowmon Products
- Flowmon
- Documentation
TACACS+ and tenants
In the current version, users from LDAP and TACACS+ are created in the base tenant only.
User authentication can be done either according to the local database or according to directory services, for example, a TACACS+ server.
Information about TACACS+ settings:
-
Server - IP address of TACACS+ server
-
Port - connection port (usually 49)
-
Server secret - the secret passphrase for connection
-
Authentication scheme - PAP and CHAP are supported
Provided connection information can be verified by clicking Check connection. You will be prompted to provide login and password information for a user recorded in the TACACS+ server directory. The system will then verify your connection.
If you can connect to the TACACS+ server, save your settings by clicking Save.
When TACACS+ authentication is enabled, every user will have to use their credentials from the TACACS+ directory to log in to the system. Unlike LDAP, it is not possible to assign a role to a Flowmon user in the TACACS+ directory. For this reason, every Flowmon user must be configured in the Configuration Center as well, where they are assigned roles. Only users configured in both TACACS+ and Configuration Center will be allowed to log into the system.
The admin user is managed in a special way. For this account, data is always taken from the local database and the TACACS+ account is never used.