Summary of AAA Configuration Tasks
After AAA configuration is complete, the device authenticates users and authorizes users. In addition, the device also records the network resource usage of users.
In theory, the device supports the combination of local, Remote Authentication Dial In User Service (RADIUS), and Huawei Terminal Access Controller Access Control System (HWTACACS) authentication, authorization, and accounting. For example, the device provides local authentication, local authorization, and RADIUS accounting.
In practice, the schemes in Table 1-21 are often used separately. Multiple authentication or authorization modes can be used in a scheme. For example, local authentication is used as a backup of RADIUS authentication and HWTACACS authentication, and local authorization is used as a backup of HWTACACS authorization.
Configuration Task |
Overview |
Task |
---|---|---|
Local authentication and authorization |
If users need to be authenticated or authorized but no RADIUS server or HWTACACS server is deployed on the network, use local authentication and authorization. Local authentication and authorization feature fast processing and low operation cost; however, the amount of local authentication and authorization information that can be stored is subject to the device hardware capacity. Local authentication and authorization are often used for administrators. |
|
RADIUS authentication, authorization, and accounting |
RADIUS protects a network from unauthorized access, and is often used on the networks demanding high security and control of remote user access. |
|
HWTACACS authentication, authorization, and accounting |
HWTACACS protects a network from unauthorized access and supports command-line authorization. HWTACACS is more reliable in transmission and encryption than RADIUS, and is more suitable for security control. |