Q12Security
Refer to the exhibit. An engineer configured TACACS+ for remote-user authentication, but it is not operating as expected. Which configuration must be applied to enable access?
← → navigate · a answer
Community votes
Discussion · 8
D 4
Selected Answer: D
This is a sample debug output from the Router, when the TACACS server is configured with the wrong pre shared key:
...
*Apr 6 13:35:07.886: TPLUS: received bad AUTHEN packet: length = 6, expected 43974
*Apr 6 13:35:07.886: TPLUS: Invalid AUTHEN packet (check keys).
https://www.cisco.com/c/en/us/support/docs/security-vpn/terminal-access-controller-access-control-system-tacacs-/200467-Troubleshoot-TACACS-Authentication-Issue.html
D 3
Selected Answer: D
D.
bash
Copy code
R1(config)# tacacs server prod
R1(config-server-tacacs)# key cisco123
This configuration sets up the TACACS+ server named "prod" with the key "cisco123". Make sure the key configured on the router matches the key configured on the TACACS+ server. Also, ensure that the TACACS+ server is reachable and properly configured to handle authentication requests from the router.
D 1
Selected Answer: D
Right
1
Please explain. I can't understand.
1
the key is "(check key)" so the issue is the credential!
1
look at the last line in the log, it says check key. so the issue is with the credentials
D 1
Selected Answer: D
The log message "TPLUS: Invalid AUTHEN packet (check keys)" from the exhibit points to a problem with the shared secret between the client and server. TACACS+ uses symmetric-key cryptography. The authenticated client in our example used a different encryption key than the server's. Option 'C' makes sure that both the client and the server encrypt their messages with the same key (shared secret, or a.k.a. a pre-configured key.)
D 1
Selected Answer: D
The last line of the exhibit says, "Check keys," which means you need to change the key (the keys do not match between client and server)