Chap Authentication; Radius; Tacacs - Nortel Secure 4134 Configuration

Security — configuration and management
Hide thumbs Also See for Secure 4134:
Table of Contents

Advertisement

72 Authentication, Authorization, and Accounting fundamentals

CHAP authentication

Challenge Handshake Authentication Protocol (CHAP) is an authentication
scheme used by Point to Point Protocol (PPP), Telnet, and SSH to validate
the identity of remote clients. CHAP periodically verifies the identity of the
client by using a three-way handshake.

RADIUS

Remote Access Dial-In User Services (RADIUS) is a distributed client/server
system that assists in securing networks against unauthorized access,
allowing a number of communication servers and clients to authenticate
user identities through a central database. The database within the RADIUS
server stores information about clients, users, passwords, and access
privileges, protected with a shared secret. RADIUS authentication is a fully
open and standard protocol defined by RFC 2865.
A RADIUS application has two components:
RADIUS server—a computer equipped with server software (for example,
a UNIX workstation) that is located at a central office or campus. It has
authentication and access information in a form that is compatible with
the client. Typically, the database in the RADIUS server stores client
information, user information, password, and access privileges, protected
with a shared secret.
RADIUS client—a switch, router, or a remote access server equipped with
client software, that typically resides on the same LAN segment as the
server. The client is the network access point between the remote users
and the server.
RADIUS authentication allows a remote server to authenticate users
attempting to log on to the router from the local console or Telnet.

TACACS

Terminal access controller access control system (TACACS+) is a security
application implemented as a client/server-based protocol that provides
centralized validation of users attempting to gain access to a router or
network access server. TACACS+ differs from RADIUS in two important
ways:
Copyright © 2007, Nortel Networks
.
TACACS+ is a TCP-based protocol.
TACACS+ uses full packet encryption, rather than just encrypting the
password (RADIUS authentication request).
Nortel Secure Router 4134
Security — Configuration and Management
NN47263-600 01.02 Standard
10.0 3 August 2007

Advertisement

Table of Contents
loading

Table of Contents