Authentication, Authorization, and Accounting
22
7705 SAR OS System Management Guide
Authorization
The 7705 SAR supports local, RADIUS, and authorization to control the actions
of specific users by applying a profile based on user name and password configurations once
network access is granted. The profiles are configured locally as well as on the RADIUS
server as VSAs. See
Vendor-Specific Attributes (VSAs)
Once a user has been authenticated using RADIUS (or another method), the 7705 SAR router
can be configured to perform authorization. The RADIUS server can be used to:
•
download the user profile to the 7705 SAR router
•
send the profile name that the node should apply to the 7705 SAR router
Profiles consist of a suite of commands that the user is allowed or not allowed to execute.
When a user issues a command, the authorization server looks at the command and the user
information and compares it with the commands in the profile. If the user is authorized to
issue the command, the command is executed. If the user is not authorized to issue the
command, then the command is not executed.
Profiles must be created on each 7705 SAR router and should be identical for consistent
results. If the profile is not present, then access is denied.
displays the following scenarios.
•
If the user is authenticated locally (on the 7705 SAR router), local authorization is
supported and remote (RADIUS) authorization cannot be performed.
•
If the user is authenticated by the RADIUS server, both local authorization and
remote (RADIUS) authorization are supported.
•
If the user is authenticated, local authorization is supported and remote
(RADIUS) authorization cannot be performed.
When authorization is configured and profiles are downloaded to the router from the
RADIUS server, the profiles are considered temporary configurations and are not saved when
the user session terminates.
Table 2: Supported Authorization Configurations
Local Authorization
RADIUS Authorization
7705 SAR configured user
Supported
Not Supported
RADIUS server configured user
Supported
Supported
server configured user
Supported
Not Supported
Summary of Contents for 7705 SAR
Page 10: ...List of Figures 10 7705 SAR OS System Management Guide...
Page 14: ...About This Guide 14 7705 SAR OS System Management Guide...
Page 64: ...Security Configuration Procedures 64 7705 SAR OS System Management Guide...
Page 168: ...Configuration Notes 168 7705 SAR OS System Management Guide...
Page 354: ...Standards and Protocol Support 354 7705 SAR OS System Management Guide...
Page 356: ...2015 Alcatel Lucent All rights reserved 3HE 09688 AAAA TQZZA Edition 01...