User Authentication Security - Centralized authentication - Configure accounting to trace activity and usage - TACACS+

Information

In larger networks, centralized authentication is almost a necessity to consistently enforce password policies and manage user accounts.

Solution

Configure accounting for each TACACS+ server.

user@host# edit system accounting destination tacplus server <IP_ADDRESS>
user@host# set accounting-port 49

See Also

http://www.juniper.net/us/en/training/jnbooks/day-one/fundamentals-series/hardening-junos-devices-checklist/

Item Details

Category: IDENTIFICATION AND AUTHENTICATION

References: 800-53|IA-2

Plugin: Juniper

Control ID: 7a2dfe3b02a5b0c23550166bf4eaaed916979ab0e1968d100ee0350275f4fcd5