- Consider clarifying the default port for TACACS+ over TLS once IANA assigns it. - Note using TLS requires the device to also implement the relevant crypto key/cert models. - Think about VRF uniqueness scenario, if needed, adjust the YANG unique statement. - "port number of TACACS+ server port number" is repetitive