SNR S2989G-8TX — настройка TACACS+ и RADIUS для сетевой безопасности [328/553]

Превью страниц Страница 328 / 553
SNR S2989G-48TX-DC [328/553] Tacacs troubleshooting
S2989G-24TX Operation Manual
Chapter 6 Security Function Configuration
6-55
Switch(config)#authentication line vty login tacacs
6.5.4
TACACS+ Troubleshooting
In configuring and using TACACS+, the TACACS+ may fail to authentication due to
reasons such as physical connection failure or wrong configurations. The user should
ensure the following:
First good condition of the TACACS+ server physical connection.
Second all interface and link protocols are in the UP state (use show interface
command).
Then ensure the TACACS+ key configured on the switch is in accordance with the
one configured on TACACS+ server.
Finally ensure to connect to the correct TACACS+ server.
6.6
RADIUS
6.6.1
Introduction to RADIUS
6.6.1.1 AAA and RADIUS Introduction
AAA is short for Authentication, Authorization and Accounting, it provide a
consistency framework for the network management safely. According to the three
functions of Authentication, Authorization, Accounting, the framework can meet the
access control for the security network: which one can visit the network device, which
access-level the user can have and the accounting for the network resource.
RADIUS (Remote Authentication Dial in User Service), is a kind of distributed and
client/server protocol for information exchange. The RADIUS client is usually used on
network appliance to implement AAA in cooperation with 802.1x protocol. The RADIUS
server maintains the database for AAA, and communicates with the RADIUS client
through RADIUS protocol. The RADIUS protocol is the most common used protocol in the
AAA framework.
6.6.1.2 Message structure for RADIUS
The RADIUS protocol uses UDP to deliver protocol packets. The packet format is
shown as below.

Содержание

666

Узнайте, как правильно настраивать TACACS+ и RADIUS для обеспечения безопасности сети. Решения проблем и основы аутентификации, авторизации и учета.