Configuring Authentication, Authorization, and Accounting
10
Configuring Authentication,
Authorization, and Accounting
This chapter describes how to control access to the switch management
interface using authentication and authorization. It also describes how to
record this access using accounting. Together the three services are referred to
by the acronym AAA.
The topics covered in this chapter include:
• AAA Overview
• Authentication
• Authorization
• Accounting
• Authentication Examples
• Authorization Examples
• Using RADIUS Servers to Control Management Access
• Using TACACS+ Servers to Control Management Access
• Default Configurations
AAA Overview
AAA is a framework for configuring management security in a consistent way.
Three services make up AAA:
• Authentication—Validates the user identity. Authentication takes place
before the user is allowed access to switch services.
• Authorization—Determines which services the user is allowed to access.
• Accounting—Collects and sends security information about users and
commands.