3Com Switch 4800G 24-Port Configuration Manual page 748

Switch 4800g family 24-port, pwr 24-port, 48-port, pwr 48-port, 24-port sfp
Hide thumbs Also See for Switch 4800G 24-Port:
Table of Contents

Advertisement

748
C
53: AAA/RADIUS/HWTACACS C
HAPTER
ONFIGURATION
Figure 227 AAA networking diagram
User
When a user tries to establish a connection to the NAS and obtain the rights to
access other networks or some network resources, the NAS authenticates the user
or the corresponding connection. The NAS can also transparently pass the user
authentication, authorization and accounting information to the server (RADIUS
server or HWTACACS server). The RADIUS/HWTACACS protocol defines how to
exchange user information between a NAS and a server.
In the AAA network shown in Figure 227, there is a RADIUS server and a
HWTACACS server. You can determine the authentication, authorization and
accounting scheme according to the actual requirements. For example, you can
use the RADIUS server for authentication and authorization, and the HWTACACS
server for accounting.
The three security functions are described as follows:
Authentication: Identifies remote users and judges whether a user is legal.
Authorization: Grants different users different rights. For example, a user
logging into the server can be granted the permission to access and print the
files in the server.
Accounting: Records all network service usage information of users, including
the service type, start and end time, and traffic. In this way, accounting can be
used for not only accounting itself, but also network security surveillance.
You can use AAA to provide only one or two security functions, if desired. For
example, if your company only wants employees to be authenticated before they
access specific resources, you can configure only an authentication server. If the
network usage information is expected to be recorded, you also need to configure
an accounting server.
As mentioned above, AAA provides a uniform framework to implement network
security management. It is a security mechanism that enables authenticated and
authorized entities to access specific resources and records operations by the
entities. The AAA framework thus allows for excellent scalability and centralized
user information management.
NAS
RADIUS server
HWTACACS server
Internet

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents