
1.1 AAA Overview
Authentication, Authorization, and Accounting (AAA) is a security technology.
Security Functions Provided by AAA
AAA provides the following security functions:
l
Authentication: checks whether a user is allowed to access a network.
l
Authorization: authorizes a user to use specific services.
l
Accounting: records all the operations performed by a user and the service type, start time,
and data traffic.
A user can use one or more security services. For example, if a company only needs to
authenticate employees that access certain network resources, only an authentication server is
needed. If the company also needs to record operations performed by employees, an additional
accounting server is needed.
AAA Architecture
AAA uses the client/server model, as shown in
extensibility and is convenient for centralized management of user information.
Figure 1-1
AAA architecture
Access user
Router
Server
The Router authenticates a user that wants to access the network through the Router. The Router
delivers authentication, authorization, and accounting information to an AAA server (a RADIUS
server or an HWTACACS server).
1.2 AAA Features Supported by the AR1200-S
The AR1200-S supports RADIUS and HWTACACS authentication, authorization, and
accounting (AAA), and also local authentication and authorization.
RADIUS Authentication, Authorization, and Accounting
RADIUS uses the client/server model and protects a network from unauthorized access. It is
often used on networks that require high security and control of remote user access.
RADIUS messages are encapsulated in User Datagram Protocol (UDP) packets. RADIUS
ensures reliability of information exchanged between the RADIUS server and client by using
the timer, retransmission mechanism, and secondary server. RADIUS integrates authentication
and authorization. RADIUS integrates authentication and authorization, and RADIUS
authentication response packets carry authorization information.
Huawei AR1200-S Series Enterprise Routers
Configuration Guide - Security
1 AAA Configuration
Issue 02 (2012-03-30)
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
2