- Products
- Learn
- Local User Groups
- Partners
- More
AI Security Masters
E1: How AI is Reshaping Our World
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hello guys,
I have a few questions regarding TACACS+ authentication on MDM and SMS appliances. As far as I know you can configure TACACS servers via the web UI and clish for GAiA itself and also via the related SmartConsole objects (Objects => New => More => Server => More => TACACS) when it comes to SmartConsole access. As far as I understand these are three different configuration approaches for 2 different config goals. This means, that the GAiA (clish + web UI) config is absolutely not related to the SmartConsole TACACS+ authentication.
In detail; you need to specify the same server twice if you want to use it for GAiA access and SmartConsole access.
Is my assumption correct? Or can the GAiA TACACS config get replicated to the actual "management product configuration" of the SMS/MDM?
And one final question; is there any way to test a TACACS configuration on a gateway or MDM/SMS? I mean sure, you can just try to log in. But especially if you have configured more than one server and want to test the secondary one a command to test the related config and connection would be great. (The only way to test TACACS auth. for a secondary server I currently know is to disable the connection to the primary one, which is not really a decent solution.)
Regards,
Maik
*push*
*push*
One last attempt - if that does not help I can accept that this thread is dead 😛
Hey Jerry,
Thanks for your reply.
I have already read both SKs and I am familiar with the general tacacs config within GAiA. 🙂
My questions were;
- is it possible to configure tacacs on the GAiA level on a SMS/MDM and adapt this config for the SmartConsole access later?
- are there any commands to verify a tacacs config - especially related to scenarios where you have a secondary tacacs server that won't be used unless the first one fails. [The only way I know to verify if everything works is by logging in with a tacacs user - to verify the secondary tacacs you need to disable any connection to the primary one.]
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 16 | |
| 15 | |
| 7 | |
| 5 | |
| 5 | |
| 5 | |
| 4 | |
| 4 | |
| 4 | |
| 4 |
Tue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsThu 08 Jan 2026 @ 05:00 PM (CET)
AI Security Masters Session 1: How AI is Reshaping Our WorldAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY