Skip to Content
Hardening Cisco Routers
book

Hardening Cisco Routers

by Thomas Akin
February 2002
Intermediate to advanced
190 pages
4h 56m
English
O'Reilly Media, Inc.
Content preview from Hardening Cisco Routers

Chapter 5. AAA Access Control

AAA stands for authentication, authorization, accounting. This chapter will cover the authentication and authorization aspects of AAA, leaving the accounting details for Chapter 11. AAA access control provides much greater scalability and functionality than the basic access control methods discussed in Chapter 3. AAA can use local router configuration, TACACS+, RADIUS, and Kerberos for authentication and can utilize a TACACS+ or RADIUS for authorization.

TACACS+ and RADIUS can be used both for authentication and authorization, while Kerberos can be used only for authentication. Cisco-only networks usually choose TACACS+ because of its enhanced features. TACACS+, however, is proprietary to Cisco. Networks using equipment from multiple vendors usually choose RADIUS for its interoperability. Finally, organizations with existing Kerberos access servers can configure their routers to use those servers to control access to Cisco routers.

Enabling AAA

To use any of these authentication and authorization methods, you must first enable AAA on the router. The general steps for enabling AAA are:

  1. Turn on AAA with the aaa new-model command.

  2. Configure security protocol information if using an access control server (ACS).

  3. Define methods that specify the type and order of authentication with the aaa authentication command.

  4. Apply the authentication methods to each line and/or enable access.

  5. Configure AAA authorization, if needed, with the aaa authorization command.

Local Authentication ...

Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Start your free trial

You might also like

CCNA Cyber Ops SECFND 210-250

CCNA Cyber Ops SECFND 210-250

Omar Santos

Publisher Resources

ISBN: 0596001665Errata Page