RADIUS versus TACACS+
High-yield CISSP comparison: RADIUS commonly supports user or network access, classic implementations use UDP, and mainly protect the Access-Request User-Password; TACACS+ commonly supports device administration, uses TCP or 49, separates AAA, and protects the packet body—more precisely called obfuscation by RFC 8907.
Common traps: Do not swap RADIUS and TACACS+ UDP or TCP characteristics. RADIUS and TACACS+ do not both protect the entire packet body in the same way. Do not overlook TACACS+'s finer-grained authorization and accounting for device administration.
Distinctions: transport: RADIUS = UDP; TACACS+ = TCP/49 protection scope: classic RADIUS = User-Password protection, not whole-body encryption; TACACS+ = body obfuscation/protection, header visible AAA semantics: RADIUS commonly couples authentication + authorization; TACACS+ separates authentication, authorization, accounting typical use: RADIUS = network access; TACACS+ = network-device administration