Skip to Content
  •  +49 (861) 88 00 32 00
COD powered by extocode GmbH
  • 0
  • Sign in
  • English (US) Français Deutsch Español Türkçe
  • Contact Us
  • Home
  • COD Overview
    Platform
    OverviewFeaturesIntegrationsPricing
    Operations & Network
    MonitoringNetworkNetwork Access Control (NAC)TACACS+Captive PortalFirewall
    Security & Resilience
    Governance, Risk & ComplianceVulnerabilities (VAS)BackupHypervisorOTPStrongholdAutomation
    Solutions & More
    NIS2 & CompliancecodPassLive demoReferencesDownloadsFAQ
  • Pricing
  • News
  • FAQ
  • About us
    • About us
    • Careers
    • References
  • Contact
COD powered by extocode GmbH
  • 0
    • Home
    • COD Overview
    • Pricing
    • News
    • FAQ
    • About us
      • About us
      • Careers
      • References
    • Contact
  •  +49 (861) 88 00 32 00
  • English (US) Français Deutsch Español Türkçe
  • Sign in
  • Contact Us

Know who is allowed to do what, and where

The COD TACACS+ module manages your in-house TACACS+ server (authentication, authorization and accounting per RFC 8907) centrally from COD, through a hardened backend proxy, fully on-premises and multi-tenant.

Who may log in to which switch, and which commands they may run there? TACACS+ answers that question, yet the server behind it is usually a black box on the command line. The COD TACACS+ module brings authentication, authorization and accounting into one interface, on the same living asset base as your operations. The frontend never talks to the management API directly.

Request a live demoDownload datasheet

Know who is allowed to do what, and where

Your AAA server, managed from COD

The Network → TACACS+ area drives your own RFC 8907 server through a hardened backend proxy, with a dedicated connection per site. Instead of maintaining configuration files on the command line, you work in one interface, on the same living data set as the rest of your operations.

  • Dashboard built from widgets: health, coverage, activity and accounting as a customizable grid per user
  • Role coverage matrix (user groups × device groups) makes gaps in coverage visible
  • Refreshes regularly on its own, near real time, without you having to reload

Users, groups and NAS clients

You maintain users, groups and the devices to be connected in one place. You set associations by drag and drop instead of editing text files.

  • Manage users and user groups centrally, associations by drag and drop
  • Clients (your NAS devices) and client groups in the same place
  • Identify clients by their certificate identity (IP or DNS mode), DNS clients even without a fixed IP

Authorization with a role simulator

Under Access Control you define authorization rules, roles and command sets. Before a rule goes live, you check in the role simulator what it actually does, against the real policy, without contacting anything real.

  • Authorization rules (PERMIT/DENY), roles and pattern-based command sets with a regex tester
  • Role simulator: evaluates user × client × command against the real policy (PERMIT, DENY, no match)
  • A clearly visible simulation banner, nothing real is contacted, only the policy is evaluated

Accounting with a live log

Every session is logged, who, what, where and when. When needed you switch on the live log and watch new records come in continuously.

  • Accounting with session records, filters and expandable detail rows
  • Switchable live log with an adjustable interval
  • Activity probe: uses the accounting records to check whether a client actually speaks TACACS+ (active, idle, no traffic)

Part of the COD platform

TACACS+ is not a siloed tool but a module of the Central Operations Dashboard, on the same living data set as network, assets, firewall and GRC.

  • Multi-tenant and role-based (LDAP/AD or local users), site-scoped
  • Fully deployable on-premises, full control of your data, no detour through third-party clouds
  • Direct connection to the asset inventory: the client dialog takes the IP from the asset

Frequently asked questions

Does COD ship its own TACACS+ server?

COD manages your in-house TACACS+ server (RFC 8907 daemon) through a hardened backend proxy, with a dedicated connection per site. Management runs entirely in COD, and the frontend never talks to the management API directly. This keeps control central and traceable.

Does COD check via SSH whether TACACS+ is configured on a switch?

No. COD does not access your devices via SSH and does not read any configuration. The diagnosis is the accounting-based activity probe: it uses the accounting records to detect whether a client actually speaks TACACS+ (active, idle or no traffic). Devices with no accounting at all may not appear, the probe is deliberately honest and passes no automatic false verdict.

What does the role simulator do?

The role simulator evaluates the combination of user, client and command against your real policy and shows the result (PERMIT, DENY or no match). This lets you check a rule before it takes effect in production. A clearly visible simulation banner makes clear that nothing real is contacted.

See all questions in the FAQ →

See TACACS+ live

Request a live demo and see the TACACS+ module hands-on in your own environment, or download the datasheet with all features compactly on one page.

Request a live demoDownload datasheet

Folgen Sie uns
​
  • COD Overview
  • Features
  • Pricing
  • Integrations
  • NIS2
  • codPass
  • References
  • Downloads
  • FAQ
  • Contact

Kotzinger Straße 21 • 83278 Traunstein • Deutschland

  • ​+49 (861) 88 00 32 00
  • ​info@extoco.de
Datenschutz Impressum ​
Copyright © extocode GmbH
English (US) Français Deutsch Español Türkçe

We use cookies to provide you a better user experience on this website. Privacy Policy

Decline Accept