Know who is allowed to do what, and where
The COD TACACS+ module manages your in-house TACACS+ server (authentication, authorization and accounting per RFC 8907) centrally from COD, through a hardened backend proxy, fully on-premises and multi-tenant.
Who may log in to which switch, and which commands they may run there? TACACS+ answers that question, yet the server behind it is usually a black box on the command line. The COD TACACS+ module brings authentication, authorization and accounting into one interface, on the same living asset base as your operations. The frontend never talks to the management API directly.
Your AAA server, managed from COD
The Network → TACACS+ area drives your own RFC 8907 server through a hardened backend proxy, with a dedicated connection per site. Instead of maintaining configuration files on the command line, you work in one interface, on the same living data set as the rest of your operations.
- Dashboard built from widgets: health, coverage, activity and accounting as a customizable grid per user
- Role coverage matrix (user groups × device groups) makes gaps in coverage visible
- Refreshes regularly on its own, near real time, without you having to reload
Users, groups and NAS clients
You maintain users, groups and the devices to be connected in one place. You set associations by drag and drop instead of editing text files.
- Manage users and user groups centrally, associations by drag and drop
- Clients (your NAS devices) and client groups in the same place
- Identify clients by their certificate identity (IP or DNS mode), DNS clients even without a fixed IP
Authorization with a role simulator
Under Access Control you define authorization rules, roles and command sets. Before a rule goes live, you check in the role simulator what it actually does, against the real policy, without contacting anything real.
- Authorization rules (PERMIT/DENY), roles and pattern-based command sets with a regex tester
- Role simulator: evaluates user × client × command against the real policy (PERMIT, DENY, no match)
- A clearly visible simulation banner, nothing real is contacted, only the policy is evaluated
Accounting with a live log
Every session is logged, who, what, where and when. When needed you switch on the live log and watch new records come in continuously.
- Accounting with session records, filters and expandable detail rows
- Switchable live log with an adjustable interval
- Activity probe: uses the accounting records to check whether a client actually speaks TACACS+ (active, idle, no traffic)
Part of the COD platform
TACACS+ is not a siloed tool but a module of the Central Operations Dashboard, on the same living data set as network, assets, firewall and GRC.
- Multi-tenant and role-based (LDAP/AD or local users), site-scoped
- Fully deployable on-premises, full control of your data, no detour through third-party clouds
- Direct connection to the asset inventory: the client dialog takes the IP from the asset
Frequently asked questions
See TACACS+ live
Request a live demo and see the TACACS+ module hands-on in your own environment, or download the datasheet with all features compactly on one page.