Operation Manual - Security
Quidway S3500 Series Ethernet Switches
Chapter 3 AAA and RADIUS Protocol Configuration
Huawei Technologies Proprietary
3-1
Chapter 3 AAA and RADIUS Protocol
Configuration
3.1 AAA and RADIUS Protocol Overview
3.1.1 AAA Overview
Authentication, Authorization and Accounting (AAA) provide a uniform framework used
for configuring these three security functions to implement the network security
management.
The network security mentioned here refers to access control and it includes:
z
Which user can access the network server?
z
Which service can the authorized user enjoy?
z
How to keep accounts for the user who is using network resource?
Accordingly, AAA shall provide the following services:
z
Authentication: authenticates if the user can access the network server.
z
Authorization: authorizes the user with specified services.
z
Accounting: traces network resources consumed by the user.
Generally applying Client/Server architecture, in which client ends run as managed
sources and the servers centralize and store user information, AAA framework owns
the good scalability, and is easy to realize the control and centralized management of
user information.
3.1.2 RADIUS Protocol Overview
As mentioned above, AAA is a management framework, so it can be implemented by
some protocols. RADIUS is such a protocol frequently used.
I. What is RADIUS
Remote Authentication Dial-In User Service, RADIUS for short, is a kind of distributed
information switching protocol in Client/Server architecture. RADIUS can prevent the
network from interruption of unauthorized access and it is often used in the network
environments requiring both high security and remote user access. For example, it is
often used for managing a large number of scattering dial-in users who use serial ports
and modems. RADIUS system is the important auxiliary part of Network Access Server
(NAS).
After RADIUS system is started, if the user wants to have right to access other network
or consume some network resources through connection to NAS (dial-in access server
Содержание Quidway S3500 Series
Страница 42: ...Huawei Technologies Proprietary HUAWEI Quidway S3500 Series Ethernet Switches Operation Manual Port ...
Страница 64: ...Huawei Technologies Proprietary HUAWEI Quidway S3500 Series Ethernet Switches Operation Manual VLAN ...
Страница 159: ...Huawei Technologies Proprietary HUAWEI Quidway S3500 Series Ethernet Switches Operation Manual Routing Protocol ...
Страница 266: ...Huawei Technologies Proprietary HUAWEI Quidway S3500 Series Ethernet Switches Operation Manual Multicast ...
Страница 323: ...Huawei Technologies Proprietary HUAWEI Quidway S3500 Series Ethernet Switches Operation Manual QoS ACL ...
Страница 402: ...Huawei Technologies Proprietary HUAWEI Quidway S3500 Series Ethernet Switches Operation Manual Integrated Management ...
Страница 431: ...Huawei Technologies Proprietary HUAWEI Quidway S3500 Series Ethernet Switches Operation Manual STP ...
Страница 466: ...Huawei Technologies Proprietary HUAWEI Quidway S3500 Series Ethernet Switches Operation Manual Security ...
Страница 537: ...Huawei Technologies Proprietary HUAWEI Quidway S3500 Series Ethernet Switches Operation Manual Reliability ...
Страница 551: ...Huawei Technologies Proprietary HUAWEI Quidway S3500 Series Ethernet Switches Operation Manual System Management ...
Страница 654: ...Huawei Technologies Proprietary HUAWEI Quidway S3500 Series Ethernet Switches Operation Manual Auto Detecting ...
Страница 667: ...Huawei Technologies Proprietary HUAWEI Quidway S3500 Series Ethernet Switches Operation Manual Appendix ...