
23
Table 3
Primary differences between HWTACACS and RADIUS
HWTACACS RADIUS
Uses TCP, providing more reliable network
transmission.
Uses UDP, providing higher transport efficiency.
Encrypts the entire packet except for the HWTACACS
header.
Encrypts only the user password field in an
authentication packet.
Protocol packets are complicated and authorization is
independent of authentication. Authentication and
authorization can be deployed on different
HWTACACS servers.
Protocol packets are simple and authorization is
combined with authentication.
Supports authorized use of configuration commands.
The user level and AAA authorization determine which
commands you can use. A user can use only
commands at or lower than the user level and
authorized by the HWTACACS server.
Does not support authorization of configuration
commands. Which commands a user can use depends
on the level of the user and a user can use all the
commands of, or lower than, the user level.
Basic message exchange process of HWTACACS
The following example describes how HWTACACS performs user authentication, authorization,
and accounting for Telnet user. See Figure 6.