C H A P T E R
19-1
Cisco Security Appliance Command Line Configuration Guide
OL-12172-03
19
Applying AAA for Network Access
This chapter describes how to enable AAA (pronounced “triple A”) for network access.
For information about AAA for management access, see the
“Configuring AAA for System
Administrators” section on page 40-5
.
This chapter includes the following sections:
•
AAA Performance, page 19-1
•
Configuring Authentication for Network Access, page 19-1
•
Configuring Authorization for Network Access, page 19-8
•
Configuring Accounting for Network Access, page 19-14
•
Using MAC Addresses to Exempt Traffic from Authentication and Authorization, page 19-16
AAA Performance
The security appliance uses “cut-through proxy” to significantly improve performance compared to a
traditional proxy server. The performance of a traditional proxy server suffers because it analyzes every
packet at the application layer of the OSI model. The security appliance cut-through proxy challenges a
user initially at the application layer and then authenticates against standard AAA servers or the local
database. After the security appliance authenticates the user, it shifts the session flow, and all traffic
flows directly and quickly between the source and destination while maintaining session state
information.
Configuring Authentication for Network Access
This section includes the following topics:
•
Authentication Overview, page 19-2
•
Enabling Network Access Authentication, page 19-3
•
Enabling Secure Authentication of Web Clients, page 19-5
•
Authenticating Directly with the Security Appliance, page 19-6
Содержание 500 Series
Страница 38: ...Contents xxxviii Cisco Security Appliance Command Line Configuration Guide OL 12172 03 ...
Страница 45: ...P A R T 1 Getting Started and General Information ...
Страница 46: ......
Страница 277: ...P A R T 2 Configuring the Firewall ...
Страница 278: ......
Страница 354: ...17 38 Cisco Security Appliance Command Line Configuration Guide OL 12172 03 Chapter 17 Configuring NAT NAT Examples ...
Страница 561: ...P A R T 3 Configuring VPN ...
Страница 562: ......
Страница 891: ...P A R T 4 System Administration ...
Страница 892: ......
Страница 975: ...P A R T 5 Reference ...
Страница 976: ......