Menu

📰
0

Reddit - Please wait for verification

Enterprise Networking Design, Support, and Discussion·/u/ColtonConor·4 months ago
#TY9nyGSd
Reading 0:00
15s threshold

Hey all — looking for some real-world input from people running TACACS+ at scale. We’re a service provider / MSP with ~100 employees, but we manage ~30,000+ network devices (switches/routers). Most of our gear supports TACACS+, except Mikrotik, which is RADIUS-only. Current setup JumpCloud for hosted RADIUS Integrated with Entra ID (M365) Not super happy with it: No TACACS+ No IPv6 Overall feels like we’ve outgrown it What we need TACACS+ at scale (primary requirement) RADIUS (for Mikrotik + access use cases) Entra ID integration 802.1X with certificates For HQ wired/wireless + VPN We use Intune for device management Seems like we’ll need a proper PKI behind this as well IPv6 support (a lot of our infra depends on it) An API for automating device management We need to add/remove/update devices in bulk (mass onboarding/offboarding, rotating secrets, etc.) Managing network devices one-by-one in a GUI won’t scale for us Constraints Many devices are not publicly reachable If they are, it’s usually IPv6 + ACLs…

Continue reading — create a free account

Join HashtagPLUS to read full articles, follow hashtags, vote, and join the conversation.

Read More