Skip to content

Taranac

One policy core for network access

Switches and access points, Active Directory, MFA and endpoints — all authenticated and authorized through a single Taranac core. TACACS+, RADIUS and 802.1X, one source of truth for access policy, with no vendor lock-in. Free to run, self-hosted.

Interactive · live device

Try real MFA in 60 seconds

Pick a second factor, enrol it for real against a live Taranac core, and get a working login to a demo Cisco device — no signup. Everything self-destructs in 5 minutes.

Capabilities

One core, every way onto your network

Policy engine

First match wins, every protocol

Every access request — TACACS+, RADIUS or 802.1X — is evaluated against one ordered rule set. Match on who, where, when and source; the first rule that fits wins and returns the result. No per-box config, no drift between protocols — one source of truth, and a built-in tester to prove a request before you ship it.

Device administration

TACACS+ down to the command

Control exactly what each operator may do on your switches and routers. Per-command authorization, privilege levels, enable passwords and console rules — with full command accounting, so every configure and every reload is authorized and logged against a real identity.

802.1X · NAC

Port access, decided per endpoint

Authenticate every device at the edge — EAP-TLS, PEAP, EAP-TTLS/TEAP, or MAB for what can’t speak 802.1X. Taranac returns the VLAN, dACL or redirect each endpoint should get, and can bounce a live session with CoA the moment policy changes.

Identity · MFA

Your directory, your choice of MFA

Sync users and groups straight from Active Directory / LDAP across multiple domains — no duplicate accounts to maintain. Then let each user pick the second factor that suits them: push from your own Taranac MFA server, Telegram, email, or a TOTP code. Push keeps TACACS+ and RADIUS logins one tap — no typing codes into a CLI.

PKI · trust

Bring your own CA — or run ours

Do certificate-based 802.1X the way your network already works. Trust EAP-TLS clients from Taranac’s built-in CA, from AD CS, or from any third-party CA — add as many trusted and AD CAs as you need. Stand up more than one internal root too — say a separate CA for contractors — so revoking a whole group is one move. EST (RFC 7030) enrollment and CRL publication are built in — no separate PKI product.

Audit · logs

Every decision, on the record

Authentication, authorization and accounting land in immutable, partitioned logs you can search, filter and export. Forward them to your SIEM over syslog, prove changes with the built-in policy tester, and let stateful alerts fire and resolve on their own.

Config tracking · NCM

Every config change, versioned — and who made it

Back up, version and diff every device’s running config — captured over SSH, Telnet, SCP/SFTP or HTTPS on a schedule or on demand, deduped and pinned to a baseline so drift stands out at a glance. Because Taranac is already your AAA server, each change arrives with who logged in and which commands they ran — the diff and the culprit, side by side. And it can authenticate with a just-in-time password nobody ever sees: minted per collection, 32 random characters, rotated the moment the job is done. Read the config tracking guide →

Reports

Reports you assemble, not queries you write

Pick a template, set the period and filters, save it as a dataset — then stack datasets into a multi-page report. 43 templates ship in the box, across AAA, NAC, configuration and audit data. Presets come laid out by us, pixel for pixel; tables hand the display to you — show the same result as a table, bar, line or pie by pointing columns at channels. Out comes a branded PDF, or CSV/XLSX for the flat tables, on demand or mailed on a schedule that keeps its window relative. You never write SQL — the query is ours, the question is yours. Read the reporting guide →

High availability · Pro

Cluster it so auth never goes down

Run Taranac as a 2–4 node cluster on replicated PostgreSQL, managed for you by Patroni and etcd — one read-write primary, the rest streaming replicas. Because every node answers TACACS+, RADIUS and 802.1X from its own local replica and cache, the authentication data plane never depends on the primary: point your devices at every node, and when one fails failover is automatic — only configuration writes pause for a few seconds. A Pro feature, unlocked by an HA license. Read the HA guide →

Roadmap

And there's more on the bench

Everything above already ships. What’s next follows the same line: an SNMP collector that turns raw device data into facts the platform can use, a network map where every node carries the verdict AAA gave it — coloured by trust, not by topology — and a scanner that walks a segment to answer one question: is this device supposed to be here? The roadmap lays out where Taranac came from and where it’s going, with nothing hidden behind a sales call. See the roadmap →

Pricing

Support that scales with you

Start on the free plan and add priority support or High Availability the moment your deployment matters.

Free
$0 · forever
  • Everything, self-hosted — no node caps
  • One open support ticket
  • AI first line that knows the docs
  • Full documentation
Start free →
Backer
$10 · /month
  • Everything in Free
  • Your tickets jump the queue
  • Support straight from the maker
  • Need an invoice? We bill your company instead
Back on Patreon →
HA · full year
$720 · one-time
  • High Availability — up to 8 nodes
  • A full year of priority support
  • Best value for production
  • A direct line as you grow

HA nodes are permanent; the plan sets your support window. Not sure which fits? Ask us.

Free to run, self-hosted, yours to operate

Self-hosted in Docker, free to run for production and internal use. Licensed under the Elastic License 2.0 — no per-seat pricing, no vendor lock-in.