<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic VSNext and TACACS+ authentication - defining TACP-15 for non-local Gaia admin user in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSNext-and-TACACS-authentication-defining-TACP-15-for-non-local/m-p/269760#M60247</link>
    <description>&lt;P&gt;Hello wizards,&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;environment: 2x 19200 with R82&amp;nbsp; ElasticXL and VSNext, 10+ Virtual Systems&lt;/LI&gt;&lt;LI&gt;mission: authenticate non-local Gaia users with TACACS+&lt;/LI&gt;&lt;LI&gt;state to resolve: how to configure TACP-15 role with intended assigned privileges equal to adminRole.&amp;nbsp;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Following the information in R82 Gaia Administration Guide and recommendations from&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk98733" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk98733&lt;/A&gt;, we configured TACACS+ Server, we prepared the TACP-0 role on VSNext gateway. We created role TACP-15 with all-features. Trying to allow TACP-15 to all virtual systems we've received following error:&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;&lt;SPAN&gt;[Global]:0&amp;gt;&lt;/SPAN&gt; add rba tole TACP-15 domain-type System all-features&lt;BR /&gt;&lt;SPAN&gt;[Global]:0&amp;gt;&lt;/SPAN&gt; add rba role TACP-15 virtual-system-access all&lt;BR /&gt;NMSRBA0429  The following features: CloningGroup, aaa-servers, backup, command, configuration, cron, expert, expert-authentication-method, expert-password, expert-password-hash, ftw, group, grub2-password, grub2-password-hash, rba, scheduled_backup, snapshot, user, are restricted to global users only, and therefore cannot be added to roles with specific VS access.&lt;/PRE&gt;&lt;P&gt;Is there any document, guide with examples related to configuration TACACS+ authentication in VSNext environment? All documents I've found till now looks like related to Legacy VSX. Is there any known difference between VSNext and Legacy VSX related to TACACS+ authentication? Any hints what features should be assigned to admin role ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I know a lot of questions, not ultimate solutions are expected, but any tips, hints and opinions to topic are welcome.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;milo&lt;/P&gt;</description>
    <pubDate>Thu, 05 Feb 2026 06:55:13 GMT</pubDate>
    <dc:creator>m1l0514v</dc:creator>
    <dc:date>2026-02-05T06:55:13Z</dc:date>
    <item>
      <title>VSNext and TACACS+ authentication - defining TACP-15 for non-local Gaia admin user</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSNext-and-TACACS-authentication-defining-TACP-15-for-non-local/m-p/269760#M60247</link>
      <description>&lt;P&gt;Hello wizards,&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;environment: 2x 19200 with R82&amp;nbsp; ElasticXL and VSNext, 10+ Virtual Systems&lt;/LI&gt;&lt;LI&gt;mission: authenticate non-local Gaia users with TACACS+&lt;/LI&gt;&lt;LI&gt;state to resolve: how to configure TACP-15 role with intended assigned privileges equal to adminRole.&amp;nbsp;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Following the information in R82 Gaia Administration Guide and recommendations from&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk98733" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk98733&lt;/A&gt;, we configured TACACS+ Server, we prepared the TACP-0 role on VSNext gateway. We created role TACP-15 with all-features. Trying to allow TACP-15 to all virtual systems we've received following error:&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;&lt;SPAN&gt;[Global]:0&amp;gt;&lt;/SPAN&gt; add rba tole TACP-15 domain-type System all-features&lt;BR /&gt;&lt;SPAN&gt;[Global]:0&amp;gt;&lt;/SPAN&gt; add rba role TACP-15 virtual-system-access all&lt;BR /&gt;NMSRBA0429  The following features: CloningGroup, aaa-servers, backup, command, configuration, cron, expert, expert-authentication-method, expert-password, expert-password-hash, ftw, group, grub2-password, grub2-password-hash, rba, scheduled_backup, snapshot, user, are restricted to global users only, and therefore cannot be added to roles with specific VS access.&lt;/PRE&gt;&lt;P&gt;Is there any document, guide with examples related to configuration TACACS+ authentication in VSNext environment? All documents I've found till now looks like related to Legacy VSX. Is there any known difference between VSNext and Legacy VSX related to TACACS+ authentication? Any hints what features should be assigned to admin role ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I know a lot of questions, not ultimate solutions are expected, but any tips, hints and opinions to topic are welcome.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;milo&lt;/P&gt;</description>
      <pubDate>Thu, 05 Feb 2026 06:55:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSNext-and-TACACS-authentication-defining-TACP-15-for-non-local/m-p/269760#M60247</guid>
      <dc:creator>m1l0514v</dc:creator>
      <dc:date>2026-02-05T06:55:13Z</dc:date>
    </item>
    <item>
      <title>Re: VSNext and TACACS+ authentication - defining TACP-15 for non-local Gaia admin user</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSNext-and-TACACS-authentication-defining-TACP-15-for-non-local/m-p/269825#M60248</link>
      <description>&lt;P&gt;In Legacy VSX, much of the OS-level VS configuration comes from Security Management and cannot be done through Gaia OS directly.&lt;BR /&gt;This concept is reinforced by the fact there are VSX Gateway specific objects with Legacy VSX installations.&lt;BR /&gt;That also means that common settings (like interfaces/routes) apply to all VSes.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In VSNext, the OS-level VS is defined on the gateway itself and VSes are defined as regular gateway objects.&lt;BR /&gt;Unlike Legacy VSX, you can have VSes managed by completely different Security Managements in unrelated SIC domains (either standalone or multi-domain management).&lt;BR /&gt;Also, you can use standard mechanisms (WebUI/clish) to affect OS-level VS changes (e.g. add interfaces/routes).&lt;/P&gt;
&lt;P&gt;All of which suggests that the relevant configurations for VS access need to be applied at the VS level.&lt;BR /&gt;This means you need to apply the relevant configuration in the context of each VS (e.g. by using&amp;nbsp;&lt;BR /&gt;set virtual-system X in clish or via the WebUI).&amp;nbsp;&lt;BR /&gt;The steps should otherwise be identical.&lt;/P&gt;</description>
      <pubDate>Thu, 05 Feb 2026 17:52:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSNext-and-TACACS-authentication-defining-TACP-15-for-non-local/m-p/269825#M60248</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2026-02-05T17:52:59Z</dc:date>
    </item>
    <item>
      <title>Re: VSNext and TACACS+ authentication - defining TACP-15 for non-local Gaia admin user</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSNext-and-TACACS-authentication-defining-TACP-15-for-non-local/m-p/269834#M60249</link>
      <description>&lt;P&gt;I did have a TAC case related to this, and legacy VSX running R82.&amp;nbsp; However the issue we had related to being in expert mode and switching into VS's, which could not be done (been a while since I looked at this though).&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 05 Feb 2026 20:18:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSNext-and-TACACS-authentication-defining-TACP-15-for-non-local/m-p/269834#M60249</guid>
      <dc:creator>genisis__</dc:creator>
      <dc:date>2026-02-05T20:18:46Z</dc:date>
    </item>
    <item>
      <title>Re: VSNext and TACACS+ authentication - defining TACP-15 for non-local Gaia admin user</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSNext-and-TACACS-authentication-defining-TACP-15-for-non-local/m-p/269847#M60250</link>
      <description>&lt;P&gt;Expert mode is a different beast for sure.&lt;/P&gt;
&lt;P&gt;Legacy VSX was created before Linux had &lt;A href="https://en.wikipedia.org/wiki/Linux_namespaces" target="_self"&gt;Namespaces&lt;/A&gt; support.&lt;BR /&gt;Not entirely clear to what extent it is being used, however.&lt;/P&gt;
&lt;P&gt;Meanwhile, VSNext was designed with Linux Namespaces in mind.&lt;BR /&gt;Perhaps this applies in the Expert shell, but haven't seen myself.&lt;/P&gt;</description>
      <pubDate>Fri, 06 Feb 2026 00:48:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSNext-and-TACACS-authentication-defining-TACP-15-for-non-local/m-p/269847#M60250</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2026-02-06T00:48:58Z</dc:date>
    </item>
    <item>
      <title>Re: VSNext and TACACS+ authentication - defining TACP-15 for non-local Gaia admin user</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSNext-and-TACACS-authentication-defining-TACP-15-for-non-local/m-p/275851#M105066</link>
      <description>&lt;P&gt;Dear friends,&amp;nbsp;&lt;/P&gt;&lt;P&gt;just very short update.&amp;nbsp;&lt;/P&gt;&lt;P&gt;The need for authenticated access to Gaia management we resolved by using RADIUS authentication.&lt;/P&gt;</description>
      <pubDate>Tue, 21 Apr 2026 07:00:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSNext-and-TACACS-authentication-defining-TACP-15-for-non-local/m-p/275851#M105066</guid>
      <dc:creator>m1l0514v</dc:creator>
      <dc:date>2026-04-21T07:00:58Z</dc:date>
    </item>
    <item>
      <title>Re: VSNext and TACACS+ authentication - defining TACP-15 for non-local Gaia admin user</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSNext-and-TACACS-authentication-defining-TACP-15-for-non-local/m-p/275869#M105069</link>
      <description>&lt;P&gt;Are you able to share the solution as I suspect configuration on GAIA and ISE are needed.&lt;/P&gt;</description>
      <pubDate>Tue, 21 Apr 2026 10:16:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSNext-and-TACACS-authentication-defining-TACP-15-for-non-local/m-p/275869#M105069</guid>
      <dc:creator>genisis__</dc:creator>
      <dc:date>2026-04-21T10:16:28Z</dc:date>
    </item>
  </channel>
</rss>

