Safari Books Online is a digital library providing on-demand subscription access to thousands of learning resources.
Configuring Cisco Secure ACS to respond as a TACACS+ server is just like configuring it to respond as a RADIUS server except that in the Authenticate Using drop-down menu you will choose TACACS+ (Cisco IOS) rather than RADIUS (Cisco Aironet). If you already added the WLC as a AAA client, you must use a different hostname than previously used for the TACACS+ client entry.
When configuring TACACS+ roles in Cisco Secure ACS you need to make sure that Shell (exec) is chosen under TACACS+ Services. Then you create a custom service that uses the Common protocol and you create custom attributes for that service using the format rolen=ROLE. You can enter one or more roles, with one role per line. For instance, if you wanted to assign RW permissions for the Security and Management menu options, you would assign roles as follows: