With Radius its a simple yes know answer from the Server, authorised on username and password. So its much like moving the local login data base over to a central server. But you cant for instance set up on the server side what privlage level a user will have on the Radius server. you have to set up the access level on the switch/router, and just use the Radius server to authentice if the user uses the correct password.
however with a TACACS+ server you are able to get much more granular, Ie you can configure on the server what individual commands the users have.
SO TACACS give you much more central control but it is Propriority so you have to pay.
With Radius its a simple yes know answer from the Server, authorised on username and password. So its much like moving the local login data base over to a central server. But you cant for instance set up on the server side what privlage level a user will have on the Radius server. you have to set up the access level on the switch/router, and just use the Radius server to authentice if the user uses the correct password.
however with a TACACS+ server you are able to get much more granular, Ie you can configure on the server what individual commands the users have.
SO TACACS give you much more central control but it is Propriority so you have to pay.