- Everything, self-hosted — no node caps
- One open support ticket
- AI first line that knows the docs
- Full documentation
Taranac
One policy core for network access
Switches and access points, Active Directory, MFA and endpoints — all authenticated and authorized through a single Taranac core. TACACS+, RADIUS and 802.1X, one source of truth for access policy, with no vendor lock-in. Free to run, self-hosted.
Interactive · live device
Try real MFA in 60 seconds
Pick a second factor, enrol it for real against a live Taranac core, and get a working login to a demo Cisco device — no signup. Everything self-destructs in 5 minutes.
Capabilities
One core, every way onto your network
Policy engine
First match wins, every protocol
Every access request — TACACS+, RADIUS or 802.1X — is evaluated against one ordered rule set. Match on who, where, when and source; the first rule that fits wins and returns the result. No per-box config, no drift between protocols — one source of truth, and a built-in tester to prove a request before you ship it.
Device administration
TACACS+ down to the command
Control exactly what each operator may do on your switches and routers.
Per-command authorization, privilege levels, enable passwords and console
rules — with full command accounting, so every configure and every reload
is authorized and logged against a real identity.
802.1X · NAC
Port access, decided per endpoint
Authenticate every device at the edge — EAP-TLS, PEAP, EAP-TTLS/TEAP, or MAB for what can’t speak 802.1X. Taranac returns the VLAN, dACL or redirect each endpoint should get, and can bounce a live session with CoA the moment policy changes.
Identity · MFA
Your directory, your choice of MFA
Sync users and groups straight from Active Directory / LDAP across multiple domains — no duplicate accounts to maintain. Then let each user pick the second factor that suits them: push from your own Taranac MFA server, Telegram, email, or a TOTP code. Push keeps TACACS+ and RADIUS logins one tap — no typing codes into a CLI.
PKI · trust
Bring your own CA — or run ours
Do certificate-based 802.1X the way your network already works. Trust EAP-TLS clients from Taranac’s built-in CA, from AD CS, or from any third-party CA — add as many trusted and AD CAs as you need. Stand up more than one internal root too — say a separate CA for contractors — so revoking a whole group is one move. EST (RFC 7030) enrollment and CRL publication are built in — no separate PKI product.
Audit · logs
Every decision, on the record
Authentication, authorization and accounting land in immutable, partitioned logs you can search, filter and export. Forward them to your SIEM over syslog, prove changes with the built-in policy tester, and let stateful alerts fire and resolve on their own.
Config tracking · NCM
Every config change, versioned — and who made it
Back up, version and diff every device’s running config — captured over SSH, Telnet, SCP/SFTP or HTTPS on a schedule or on demand, deduped and pinned to a baseline so drift stands out at a glance. Because Taranac is already your AAA server, each change arrives with who logged in and which commands they ran — the diff and the culprit, side by side. And it can authenticate with a just-in-time password nobody ever sees: minted per collection, 32 random characters, rotated the moment the job is done. Read the config tracking guide →
Reports
Reports you assemble, not queries you write
Pick a template, set the period and filters, save it as a dataset — then stack datasets into a multi-page report. 43 templates ship in the box, across AAA, NAC, configuration and audit data. Presets come laid out by us, pixel for pixel; tables hand the display to you — show the same result as a table, bar, line or pie by pointing columns at channels. Out comes a branded PDF, or CSV/XLSX for the flat tables, on demand or mailed on a schedule that keeps its window relative. You never write SQL — the query is ours, the question is yours. Read the reporting guide →
High availability · Pro
Cluster it so auth never goes down
Run Taranac as a 2–4 node cluster on replicated PostgreSQL, managed for you by Patroni and etcd — one read-write primary, the rest streaming replicas. Because every node answers TACACS+, RADIUS and 802.1X from its own local replica and cache, the authentication data plane never depends on the primary: point your devices at every node, and when one fails failover is automatic — only configuration writes pause for a few seconds. A Pro feature, unlocked by an HA license. Read the HA guide →
Roadmap
And there's more on the bench
Everything above already ships. What’s next follows the same line: an SNMP collector that turns raw device data into facts the platform can use, a network map where every node carries the verdict AAA gave it — coloured by trust, not by topology — and a scanner that walks a segment to answer one question: is this device supposed to be here? The roadmap lays out where Taranac came from and where it’s going, with nothing hidden behind a sales call. See the roadmap →
Pricing
Support that scales with you
Start on the free plan and add priority support or High Availability the moment your deployment matters.
- Everything in Free
- Your tickets jump the queue
- Support straight from the maker
- Need an invoice? We bill your company instead
- High Availability — up to 8 nodes
- 1 month of priority support
- Signed license, bound to your cluster
- Runs forever — support is the window
- High Availability — up to 8 nodes
- A full year of priority support
- Best value for production
- A direct line as you grow
HA nodes are permanent; the plan sets your support window. Not sure which fits? Ask us.
Let's get you on HA
Tell us where to send the invoice and payment link — we'll take it from there.
Thanks — we'll get back to you soon.
Prefer email? support@taranac.pro
Free to run, self-hosted, yours to operate
Self-hosted in Docker, free to run for production and internal use. Licensed under the Elastic License 2.0 — no per-seat pricing, no vendor lock-in.