Aaa For Mpls L3Vpns - HP VSR1000 Security Configuration Manual

Virtual services router
Table of Contents

Advertisement

No accounting—The NAS does not perform accounting for the users.
Local accounting—Local accounting is implemented on the NAS. It counts and controls the number
of concurrent users who use the same local user account, but does not provide statistics for
charging.
Remote accounting—The NAS works with a RADIUS server or HWTACACS server for accounting.
You can configure backup methods to be used when the remote server is not available.
In addition, the device provides the following login services to enhance device security:
Command authorization—Enables the NAS to let the authorization server determine whether a
command entered by a login user is permitted. Login users can execute only commands permitted
by the authorization server. For more information about command authorization, see Fundamentals
Configuration Guide.
Command accounting—When command authorization is disabled, command accounting enables
the accounting server to record all valid commands executed on the device. When command
authorization is enabled, command accounting enables the accounting server to record all
authorized commands. For more information about command accounting, see Fundamentals
Configuration Guide.
User role authentication—Authenticates each user who wants to obtain another user role without
logging out or getting disconnected. For more information about user role authentication, see
Fundamentals Configuration Guide.

AAA for MPLS L3VPNs

You can deploy AAA across VPNs in an MPLS L3VPN scenario where clients in different VPNs are
centrally authenticated. The deployment enables forwarding of RADIUS and HWTACACS packets
across MPLS VPNs. For example, as shown in
the left side of the MPLS backbone serves as a NAS. The NAS transparently delivers the AAA packets of
private users in VPN 1 and VPN 2 to the AAA servers in VPN 3 for centralized authentication.
Authentication packets of private users in different VPNs do not affect each other.
Figure 9 Network diagram
This feature can also help an MCE to implement portal authentication for VPNs. For more information
about MCE, see MPLS Configuration Guide. For more information about portal authentication, see
"Configuring portal
authentication."
Figure
9, you can deploy AAA across the VPNs. The PE at
13

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents