> Source: [sk69703](https://support.checkpoint.com/results/sk/sk69703)

# sk69703 - TACACS+ support in Gaia OS

| Property | Value |
|----------|-------|
| Solution ID | sk69703 |
| Date Created | 2012-03-28 |
| Last Modified | 2022-11-27 |
| Technical Level | General |
| Products | Security Gateway, Security Management Server |
| Versions | R81.20, R81.10 (EOS), R81.20, R81 (EOS), R81.10 (EOS), R81 (EOS) |
| OS | Gaia |

## Solution

**TACACS+ support in Gaia OS is limited:**

|-------------------------------------|---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| Version                             | TACACS+ support                                                                                                                                                                                                           |
| R75.40                              | R75.40 Gaia OS does not provide support for authentication with TACACS+ external server. **Upgrade to R75.40 Gaia Feature Release (Gaia+) and higher.**                                                                   |
| R75.40 Gaia Feature Release (Gaia+) | Authentication with single TACACS+ server. (R75.40 Gaia+ is documented in [sk67581](http://supportcontent.checkpoint.com/solutions?id=sk67581).)                                                                          |
| **R76 and higher**                  | Support for TACACS+ was improved as follows: * Authentication with multiple TACACS+ servers is now possible. * Ability to configure timeout for every TACACS+ server. * Turn On / Off authentication via TACACS+ servers. |

**To enable TACACS+ for authentication:**

* **In Gaia Portal:**

  1. Go to *User Management* section - click on *Authentication Servers*.
  2. Select *Enable TACACS+ authentication*.
  3. Click the *Add* button and fill in the TACACS server properties: priority, server IP address, shared key, timeout (in seconds).
* **In Gaia Clish:**

  1. *add aaa tacacs-servers priority VALUE server VALUE key VALUE timeout VALUE*
  2. *add rba role TACP-0 domain-type System all-features*
  3. *save config*

<br />

* **R77.30 and higher**

In SmartDashboard: *Manage \> Servers and OPSEC Applications \> New \> TACACS*

*![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk69703/TACAS1705080144.jpg)*

**Related documentation:**

* Gaia Administration Guide ([R75.40](http://supportcontent.checkpoint.com/documentation_download?id=13241), [R75.40VS](http://supportcontent.checkpoint.com/documentation_download?id=16244), [R76](http://supportcontent.checkpoint.com/documentation_download?id=22928), [R77](http://supportcontent.checkpoint.com/documentation_download?id=24828), [R80.10](https://sc1.checkpoint.com/documents/R80.10/WebAdminGuides/EN/CP_R80.10_Gaia_AdminGuide/html_frameset.htm), [R80.20](https://sc1.checkpoint.com/documents/R80.20_GA/WebAdminGuides/EN/CP_R80.20_Gaia_AdminGuide/html_frameset.htm), [R80.30](https://sc1.checkpoint.com/documents/R80.30/WebAdminGuides/EN/CP_R80.30_Gaia_AdminGuide/html_frameset.htm), [R80.40](https://sc1.checkpoint.com/documents/R80.40/WebAdminGuides/EN/CP_R80.40_Gaia_AdminGuide/Default.htm))

**Related solutions:**

* [sk101573 - How to configure Gaia OS to work with a TACACS+ server](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk101573)
* [sk92486 - Adding Multiple TACACS+ Servers in Gaia+](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk92486)
* [sk98733 - Best practices to configure Cisco ACS 5 server for TACACS+ authentication with Gaia](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk98733)
* [sk108851 - TACACS+ users with role TACP-15 fail to access Expert mode on R77.30 Gaia OS](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk108851)

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
