Benefits Of Using Aaa - Cisco nexus 5000 series Cli Configuration Manual

Hide thumbs Also See for nexus 5000 series:
Table of Contents

Advertisement

Information About AAA
S e n d f e e d b a c k t o n x 5 0 0 0 - d o c f e e d b a c k @ c i s c o . c o m
Based on the user ID and password combination that you provide, the Nexus 5000 Series switches
perform local authentication or authorization using the local database or remote authentication or
authorization using one or more AAA servers. A preshared secret key provides security for
communication between the Nexus 5000 switch and AAA servers. You can configure a common secret
key for all AAA servers or for only a specific AAA server.
AAA security provides the following services:
The Cisco NX-OS software supports authentication, authorization, and accounting independently. For
Note
example, you can configure authentication and authorization without configuring accounting.

Benefits of Using AAA

AAA provides the following benefits:
Cisco Nexus 5000 Series Switch CLI Software Configuration Guide
1-2
Authentication—Identifies users, including login and password dialog, challenge and response,
messaging support, and, encryption depending on the security protocol that you select.
Authentication is the process of verifying the identity of the person or device accessing the Nexus 5000
Series switches. This process is based on the user ID and password combination provided by the entity
trying to access the Nexus 5000 switch. The Nexus 5000 Series switches allow you to perform local
authentication (using the local lookup database) or remote authentication (using one or more RADIUS
or TACACS+ servers).
Authorization—Provides access control.
AAA authorization is the process of assembling a set of attributes that describe what the user is
authorized to perform. Authorization in Nexus 5000 Series switches is provided by attributes that
are downloaded from AAA servers. Remote security servers, such as RADIUS and TACACS+,
authorize users for specific rights by associating attribute-value (AV) pairs, which define those
rights with the appropriate user.
Accounting—Provides the method for collecting information, logging the information locally, and
sending the information to the AAA server for billing, auditing, and reporting.
The accounting feature tracks and maintains a log of every management session used to access the
Nexus 5000 Series switches. You can use this information to generate reports for troubleshooting
and auditing purposes. You can store accounting logs locally or send them to remote AAA servers.
The accounting log feature does not log the show commands. For example, the feature does not log
the show version or show module commands.
Increased flexibility and control of access configuration
Scalability
Standardized authentication methods, such as RADIUS and TACACS+
Multiple backup devices
Chapter 1
Configuring AAA
OL-16597-01

Advertisement

Table of Contents
loading

Table of Contents