ETExamTower
Q12Security

Refer to the exhibit. An engineer configured TACACS+ for remote-user authentication, but it is not operating as expected. Which configuration must be applied to enable access?

Question exhibit
← → navigate · a answer
Community votes
D
100% (6)
A
0% (0)
B
0% (0)
C
0% (0)
Discussion · 8
D 4
Selected Answer: D This is a sample debug output from the Router, when the TACACS server is configured with the wrong pre shared key: ... *Apr 6 13:35:07.886: TPLUS: received bad AUTHEN packet: length = 6, expected 43974 *Apr 6 13:35:07.886: TPLUS: Invalid AUTHEN packet (check keys). https://www.cisco.com/c/en/us/support/docs/security-vpn/terminal-access-controller-access-control-system-tacacs-/200467-Troubleshoot-TACACS-Authentication-Issue.html
D 3
Selected Answer: D D. bash Copy code R1(config)# tacacs server prod R1(config-server-tacacs)# key cisco123 This configuration sets up the TACACS+ server named "prod" with the key "cisco123". Make sure the key configured on the router matches the key configured on the TACACS+ server. Also, ensure that the TACACS+ server is reachable and properly configured to handle authentication requests from the router.
D 1
Selected Answer: D Right
1
Please explain. I can't understand.
1
the key is "(check key)" so the issue is the credential!
1
look at the last line in the log, it says check key. so the issue is with the credentials
D 1
Selected Answer: D The log message "TPLUS: Invalid AUTHEN packet (check keys)" from the exhibit points to a problem with the shared secret between the client and server. TACACS+ uses symmetric-key cryptography. The authenticated client in our example used a different encryption key than the server's. Option 'C' makes sure that both the client and the server encrypt their messages with the same key (shared secret, or a.k.a. a pre-configured key.)
D 1
Selected Answer: D The last line of the exhibit says, "Check keys," which means you need to change the key (the keys do not match between client and server)