Cisco AS5800 Specifications Page 151

  • Download
  • Add to my manuals
  • Print
  • Page
    / 334
  • Table of contents
  • TROUBLESHOOTING
  • BOOKMARKS
  • Rated. / 5. Based on customer reviews
Page view 150
4-13
Cisco AS5800 Operations, Administration, Maintenance, and Provisioning Guide
DOC-7810814=
Chapter 4 Administration
Access Service Security
Access Service Security
The Cisco AS5800 is designed to support a security paradigm providing authentication, authorization,
and accounting (AAA) security measures using RADIUS and TACACS+.
Authenticationrequires dial-in users to identify themselves and prove their identity, thus
preventing wrongful access to lines on your Cisco AS5800, or connecting through the lines directly
to network resources.
Authorizationprevents users from gaining access to particular services and devices on the
network.
Accountingprovides records for billing and other needs to determine who is connected to the
network and how long they have been connected. It does not describe how to configure accounting.
This section describes how to configure security using a local database resident on your Cisco AS5800
or using a remote security database for Terminal Access Controller Access Control System with Cisco
proprietary enhancements (TACACS+) and Remote Authentication Dial-In User Service (RADIUS).
Refer to the Local and Remote Server Authentication section on page 4-13 for local and remote
authentication definitions.
Note This section does not provide a comprehensive security overview. It does not describe how
to completely configure TACACS, Extended TACACS, access lists or RADIUS. It
presents the most commonly used security mechanisms to prevent unauthenticated and
unauthorized access to network resources through a Cisco AS5800. For a comprehensive
overview of Cisco security tools, refer to the security configuration guide in the Cisco IOS
configuration guides and command references documentation.
This section describes the following topics:
Local and Remote Server Authentication
Configuring RADIUS
Configuring TACACS+
Local and Remote Server Authentication
This section describes the differences between local and remote security databases and the basic
authentication process for each. Remote security databases described in this section include Terminal
Access Controller Access Control System with Cisco proprietary enhancements (TACACS+) and
Remote Authentication Dial-In User Service (RADIUS).
Generally the size of the network and type of corporate security policies and control determine whether
you use a local or remote security database.
Local Security Database
If you have one or two Cisco AS5800 providing access to your network, store username and password
security information on your Cisco AS5800. This is referred to as local authentication.
Page view 150
1 2 ... 146 147 148 149 150 151 152 153 154 155 156 ... 333 334

Comments to this Manuals

No comments