Support Juniper device as default.
209
Tacacs-ng is a open sources collection which are developed by Marc Huber. Reference: https://github.com/MarcJHuber/event-driven-servers.
This image provides a solution to build a TACACS+ server quicky. Furthermore, the configuration file was modified inside the container to supports authentication, authorization, and accounting for Juniper Network devices as default. It is built with basic features and parameters, and suitable for testing, lab,...You have to consider carefully about security risks before apply it for production network, or you can enhance it with more options intergrated in TACACS+ NG packages. For more information, refer this link: TACACS+ NG.
All of the needs are in directory: /tacplusng, but please put attention on these below folders and files:
├── tacplusng
│ ├── configs
│ │ └── tac_plus-ng.conf
│ ├── logs
│ │ └── acct
│ │ └── authc
│ │ └── authz
│ ├── sbin
│ │ └── tac_plus-ng
│ ├── ...
| /tacplusng/configs/tac_plus-ng.conf | configuration file, all TACACS+ server configuration are here! |
| /tacplusng/configs/acct | accounting log files, log files are generated automatically when network devices send accounting signal to server. |
| /tacplusng/configs/authc | authentication log files, log files are generated automatically when network devices send authentication signal to server. |
| /tacplusng/configs/authz | authorization log files, log files are generated automatically when network devices send authorization signal to server. |
| /tacplusng/sbin/tac_plus-ng | service execution file, it reads tac_plus-ng.conf and start the service. |
| TACACS+ published port | 0.0.0.0:49 for IPv4 and ::0/49 for IPv6 |
| IP range for network device | 10.0.0.0/16 |
| TACACS+ key | tacacs |
| Enable 15 (Cisco) | tacacs |
| Profiles |
L1Operator: Level 1 Network Operator, can view device status and device configuration (not include system login configuration) L1Operator: Level 2 Network Operator, include privilege of L1Operator, and can configure some basic features (ext: interfaces, vlans, security rules, firewall filters,...) But can not control hardware commands and others L3Operator: Level 3 Network Operator, include privilege of L1Operator, L2Operator, and can configure almost features but can not execute some commands which would cause downtime to device (ext: upgrade OS, reboot, reset,...) |
| Groups |
L1Operator, affected by L1Operator profile L2Operator, affected by L2Operator profile L3Operator, affected by L3Operator profile |
| Users and Password |
l1noc (clear text password: l1noc), member of group L1Operator l2noc (clear text passowrd: l2noc), member of group L2Operator l3noc (clear text password: l3noc), member of group L3Operator |
Note
With Cisco devices, all groups are permitted all with privilege level is 15.
Create docker volume for configs (to modify configuration file on docker host) and logs folder, you can reate your own directory then bind it.
volume create --driver local -o o=bind -o type=none -o device="<your_own_directory_path_in_docker_host>/configs" <your_config_volume_name>
volume create --driver local -o o=bind -o type=none -o device="<your_own_directory_path_in_docker_host>/logs" <your_log_volume_name>
Warning
In case you want to use bind/mount method with -v OPTION without volumn creation, please ensure that configuration file tac_plus-ng.conf is existed in docker host's bind directory before running image.
Run container
run --name="<your_container_name>" -p 49:49 -v <your_config_volume_name>:/tacplusng/configs -v <your_log_volume_name>:/tacplusng/logs -d xenoxone/tacacsng:v1.0
Refresh configuration in container shell or restart container each time when you finish configuration modification (If you run with default builtin configuration, ignore this step)
# Pre-check configuration syntax, if it has any issues, a message will be raised immediately. Otherwise, nothing happen after execution.
/tacplusng/sbin/tac_plus-ng /tacplusng/configs/tac_plus-ng.conf -P
# Rerun configuration file after checking syntax.
/tacplusng/sbin/tac_plus-ng /tacplusng/configs/tac_plus-ng.conf
Configure TACACS+ server (basic)
set system tacplus-server <container_published_ip_address> secret tacacs
set system tacplus-server <container_published_ip_address> source-address <your_network_device_ip_address_which_is_able_to_reach_tacacs_server>
Configure local username
Juniper network devices require one or more local usernames to be bound to profiles on TACACS+ server (refer this link. Therefore, we have to configure some local usernames (without password) for this.
set system login class Junior permission all
set system login class Administrator permission all
set system login class Architect permission all
set system login user l1operator uid 2002
set system login user l1operator class Junior
set system login user l2operator uid 2003
set system login user l2operator class Administrator
set system login user l3operator uid 2004
set system login user l3operator class Architect
set system authentication-order tacplus
set system authentication-order password
Note
You can set permission for each class as you want, it will be merged with permission in appropriate profiles of TACACS+ server. Please keep in mind: don't set countary actions (permit and deny) for the same permission between server and local device.
#!/usr/local/sbin/tac_plus-ng
# You have to put "#!/usr/local/sbin/tac_plus-ng" on the first line - it is not a comment line, it define the shebang syntax for entire file contents.
# TACACS+ NG support so many useful features like encrypted/hashed password for user, remote authentication via LDAP, realm, acl (white list), and more... But this is file I made for LAB, building test cases,...
# So I just use some basic features, like local plaintext password, groups, profiles, logs. That's all.
# For more details of config explaination and options, please prefer this link: https://projects.pro-bono-publico.de/event-driven-servers/doc/tac_plus-ng.html
# Thank to Marc Huber, who created TACACS+ NG!
# Configure spawned to tell the daemon the address and TCP ports to listen on, you can input many lines to init listened address and port.
# If you use this TACACS+ NG as a docker container, please do not change this id, because I built this image with port 49 exposed perpetually.
id = spawnd {
listen = { address = 0.0.0.0 port = 49 }
listen = { address = ::0 port = 49 }
}
# Tacacs plus NG main configuration.
id = tac_plus-ng {
# Define pattern and use local directory for logs. You can use syslog instead. I also put the sample configuration when using syslog servers below this local log in line 31.
log acctlog { destination = /tacplusng/logs/acct/%Y/%m/%d.log }
log authclog { destination = /tacplusng/logs/authc/%Y/%m/%d.log }
log authzlog { destination = /tacplusng/logs/authz/%Y/%m/%d.log }
# Set each type of above definitions to appropriate AAA log services.
accounting log = acctlog
authentication log = authclog
authorization log = authzlog
# Timeout interval
# Connection time out, counted by second, default is 600s.
# connection timeout = 600
# In case you want to push log to a remote syslog server, please use this below configuration, change IP address to your syslog server.
# log mylog {
# destination = 10.116.21.21 # UDP syslog
# or one of the following:
# destination = [fe80::123:4567:89ab:cdef]:514 # IPv6 UDP, with non-standard UDP port, optional
# destination = "/tmp/x.log" # plain file, async writes, optional
# destination = ">/tmp/x.log" # plain file, sync writes, optional
# destination = "|my_script.sh" # script, optional
# destination = syslog # syslog(3), optional
#
# syslog facility = MAIL # sets log facility
# syslog level = DEBUG # sets log level
# }
# authentication log = mylog
# accounting log = mylog
# authorization log = mylog
# You can specify a retire limit to have the server auto-terminate and restart its worker processes.
# retire limit = 30
# The idea is having 3 levels of network operation profiles:
# L1Operator: View-only, people can execute "show ..." commands to see statistic, the others are denied.
# L2Operator: Higher level than L1Operator, people can access to config mode, but only be able to execute some commands relate to vlans, interfaces, spanning tree and security policies...
# They are denied to see and edit configuration about login users, root authentication, clear routing statistic, clear routing process, access shell mode, or request commands.
# L3Operator: They can configure most of network features, except clear, reboot, turn-off, zeroize,...
profile L1Operator {
script {
# This if block is for network devices use Juniper config style
if (service == junos-exec) {
# Map this profile to a local username, I recommend you configure an username on your device first, put this username in 1 local device class (depend on your security policies, I can't decide it)
# For me, I create user l1operator without password on my Juniper device, and put this user to local class L1Operator with some permission.
# Please note that the commands you deny or allow on this file will be merged with permission you configured in local device. You have to test it carefully.
set local-user-name = l1operator
set deny-commands = "clear|edit|restart|request|(start shell)|configure|enable"
permit
}
# This if block is for network devices use Cisco config style
if (service == shell) {
if (cmd == "") {
# You don't have to have a local user name if it is Cisco style device.
set priv-lvl = 15
permit
}
}
}
}
profile L2Operator {
script {
if (service == junos-exec) {
set local-user-name = l2operator
set allow-configuration = "vlans|protocols lldp|protocols mstp|security policies"
set deny-commands = "clear ospf|clear bgp|clear security|restart|request|(start shell)"
set deny-configuration = "system login|system root-authentication"
permit
}
if (service == shell) {
if (cmd == "") {
set priv-lvl = 15
permit
}
}
}
}
profile L3Operator {
script {
if (service == junos-exec) {
set local-user-name = admin
set deny-commands = "restart|request system reboot|request system halt|request system power-off|request system zeroize|clear security policies|((request system software) (add|delete|rollback|in-service-upgrade))"
set deny-configuration = "system login|system root-authentication"
permit
}
if (service == shell) {
if (cmd == "") {
set priv-lvl = 15
permit
}
}
}
}
# Create groups, each above profiles has appropriate group of users, of course you can set many groups, I use the same name with profile's name for more familiar.
group L1Operator
group L2Operator
group L3Operator
# Create users, give them password and assign each user to a group. Password can be clear (plantext) or other hashing strings supported by many algorithm like MD5, SHA,... I use plaintext for testing.
# User "l1noc" has password "l1noc" and so on, you can change each user's password as you want (plaintext definition)
# Actually, an user can be assigned to more than 1 group, for example: member = L1Operator,L2Operator. It depend on your own policies for securing network access.
user l1noc {
password login = clear l1noc
member = L1Operator
}
user l2noc {
password login = clear l2noc
member = L2Operator
}
user l3noc {
password login = clear l3noc
member = L3Operator
}
# Identify which network devices can be connected to our server, any devices block inside this are inherited from father block.
host mynet {
# Define which network device's addresses are accepted for connecting to this server using TACACS+ process. This is optional because you also be able to define specific address in sub device blocks inside network-devices
address = 10.0.0.0/8
welcome banner = "\nHELLO, THIS IS TACACS+ NG SERVER, YOU ARE REACHABLE!!!\n"
key = tacacs
# Use this for Cisco style devices, to give it an enable password. I use password "tacacs"
enable 15 = clear tacacs
}
# Create ruleset, this is important to know your self design policies. For me, I assgin profiles to group, and any users are members of particular group will be affected by profile in ruleset.
ruleset {
rule {
# Enable this rule, default is enable, but I just make it more clear.
enabled = yes
script {
# If group is L1Operator, it is affected by profile L1Operator and so on.
if (member == L1Operator) { profile = L1Operator permit }
if (member == L2Operator) { profile = L2Operator permit }
if (member == L3Operator) { profile = L3Operator permit }
}
}
}
}
11/24/2024 v1.0
Content type
Image
Digest
sha256:a8071946e…
Size
20.7 MB
Last updated
almost 2 years ago
docker pull xenoxone/tacacs-ng:v1.0