Tacacs+ Authorization; Table 2: Supported Authorization Configurations - Alcatel-Lucent 7450 System Management Manual

Ethernet service switch
Hide thumbs Also See for 7450:
Table of Contents

Advertisement

Profiles consist of a suite of commands that the user is allowed or not allowed to execute. When a
user issues a command, the authorization server looks at the command and the user information
and compares it with the commands in the profile. If the user is authorized to issue the command,
the command is executed. If the user is not authorized to issue the command, then the command is
not executed.
Profiles must be created on each router and should be identical for consistent results. If the profile
is not present, then access is denied.
Table 2
When authorization is configured and profiles are downloaded to the router from the RADIUS
server, the profiles are considered temporary configurations and are not saved when the user
session terminates.

Table 2: Supported Authorization Configurations

Routerconfigured user
RADIUS server configured user
TACACS+ server configured user
When using authorization, maintaining a user database on the router is not required. User names
can be configured on the RADIUS server. User names are temporary and are not saved in the
configuration when the user session terminates. Temporary user login names and their associated
passwords are not saved as part of the configuration.

TACACS+ Authorization

TACACS+ authorization operates in one of three ways:
7450 ESS System Mangement Guide
displays the following scenarios:
Remote (RADIUS) authorization cannot be performed if authentication is done locally
(on the router).
The reverse scenario is supported if RADIUS authentication is successful and no
authorization is configured for the user on the RADIUS server, then local (router)
authorization is attempted, if configured in the authorization order.
All users who authenticate via TACACS+ can use a single common default profile that is
configured on the SR OS Router, or
Each command attempted by a user is sent to the TACACS+ server for authorization
Router
RADIUS Supplied Profile
Supported
Not Supported
Supported
Supported
Supported
Not Supported
Security
Page 29

Advertisement

Table of Contents
loading

Table of Contents