Skip to content
Sajjad Haghi
Sajjad Haghi

Network | Security | Wireless

  • Home
  • About me
Sajjad Haghi

Network | Security | Wireless

RADIUS vs. TACACS

Posted on December 13, 2025December 13, 2025 By admin

in network infrastructure if you needed to authenticate and grant some access to a user or device, surely you have about heard AAA Server.

RADIUS and TACACS are two known protocols in AAA procedure that have some diffrance.

each of them has different uses. usually, TACACS use for device authentication and RADIUS use for network authentication.

RadiusAccounting packetAuthentication PacketNO Authorization PacketStandardUDP 1812/1813 Or 1645/1646EAP Based AuthenticationOnly payload encryptedCoA
TACACSAccounting packetAuthentication PacketAuthorization PacketCISCOTCP 49XEntire packet encryptedX

In RADIUS protocol, Authorization attributes are different in each vendor and will send in authentication packet. In the other hand, because in device access we need to transfer authorization packets frequently So its suitable for network access and not suitable for device access.

BECAUSE authentication packet will send only in the beginning of connection .

TACACS’s authentication method are weak so For device access its better use TACACS protocol.

For example SSH in very secure by itself.

*** CoA ***

In Radius Protocol , authorization only perform at the beginning of connection, and it don’t run while the connection

But it has a feature named CoA (Change of authorization) that it needs to an agent installed on supplicant.

This agent sends the state of supplicant if it changed, so AAA server re-authorized the user again.

Cisco ISE Security

Post navigation

Previous post

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Categories

  • Cisco 9800
  • Cisco ISE
  • Fortigate
  • Network
  • Security
  • Wireless
©2026 Sajjad Haghi | WordPress Theme by SuperbThemes