Table 64: TACACS-Related Terms
Description
Term
Network access server. A device that provides connections to a single user,
to a network or subnetwork, and to interconnected networks. In reference
to , the NAS is the E Series router.
NAS
A program or software running on a security server that provides AAA
services using the protocol. The program processes
authentication, authorization, and accounting requests from an NAS. When
processing authentication requests, the process might respond to the NAS
with a request for additional information, such as a password.
process
The security server on which the process is running. Also
referred to as a server.
host
AAA Overview
allows effective communication of AAA information between NASs and
a central server. The separation of the AAA functions is a fundamental feature of the
design:
■
Authentication—Determines who a user is, then determines whether that user
should be granted access to the network. The primary purpose is to prevent
intruders from entering your networks. Authentication uses a database of users
and passwords.
■
Authorization—Determines what an authenticated user is allowed to do.
Authorization gives the network manager the ability to limit network services to
different users. Also, the network manager can limit the use of certain commands
to various users. Authorization cannot occur without authentication.
■
Accounting—Tracks what a user did and when it was done. Accounting can be
used for an audit trail or for billing for connection time or resources used.
Accounting can occur independent of authentication and authorization.
Central management of AAA means that the information is in a single, centralized,
secure database, which is much easier to administer than information distributed
across numerous devices. Both RADIUS and protocols are client-server
systems that allow effective communication of AAA information.
For information about RADIUS, see “Configuring Remote Access” on page 3.
Administrative Login Authentication
Fundamentally, provides the same services as RADIUS. Every
authentication login attempt on an NAS is verified by a remote process.
authentication uses three packet types. Start packets and Continue packets
are always sent by the user. Reply packets are always sent by the process.
312
■
Overview
JUNOSe 11.0.x Broadband Access Configuration Guide
Содержание JUNOSE 11.0.X MULTICAST ROUTING
Страница 6: ...vi...
Страница 28: ...xxviii Table of Contents JUNOSe 11 0 x Broadband Access Configuration Guide...
Страница 36: ...xxxvi List of Tables JUNOSe 11 0 x Broadband Access Configuration Guide...
Страница 42: ...2 Managing Remote Access JUNOSe 11 0 x Broadband Access Configuration Guide...
Страница 204: ...164 Managing RADIUS and TACACS JUNOSe 11 0 x Broadband Access Configuration Guide...
Страница 274: ...234 CLI Commands Used to Modify RADIUS Attributes JUNOSe 11 0 x Broadband Access Configuration Guide...
Страница 292: ...252 Monitoring RADIUS Relay Server JUNOSe 11 0 x Broadband Access Configuration Guide...
Страница 336: ...296 RADIUS Client Terminate Reasons JUNOSe 11 0 x Broadband Access Configuration Guide...
Страница 368: ...328 Managing L2TP JUNOSe 11 0 x Broadband Access Configuration Guide...
Страница 408: ...368 Configuring the Weighted Load Balancing Method JUNOSe 11 0 x Broadband Access Configuration Guide...
Страница 444: ...404 PPP Accounting Statistics JUNOSe 11 0 x Broadband Access Configuration Guide...
Страница 492: ...452 Monitoring Operational Status within the Current VR Context JUNOSe 11 0 x Broadband Access Configuration Guide...
Страница 494: ...454 Managing DHCP JUNOSe 11 0 x Broadband Access Configuration Guide...
Страница 510: ...470 DHCP Local Server Configuration Tasks JUNOSe 11 0 x Broadband Access Configuration Guide...
Страница 528: ...488 Configuring the Router to Work with the SRC Software JUNOSe 11 0 x Broadband Access Configuration Guide...
Страница 556: ...516 Configuring DHCP Relay Proxy JUNOSe 11 0 x Broadband Access Configuration Guide...
Страница 616: ...576 Managing the Subscriber Environment JUNOSe 11 0 x Broadband Access Configuration Guide...
Страница 632: ...592 Subscriber Management Configuration Examples JUNOSe 11 0 x Broadband Access Configuration Guide...
Страница 636: ...596 Monitoring Active IP Subscribers Created by Subscriber Management JUNOSe 11 0 x Broadband Access Configuration Guide...
Страница 672: ...632 Monitoring Active IP Subscribers Created by Subscriber Management JUNOSe 11 0 x Broadband Access Configuration Guide...
Страница 674: ...634 Managing Subscriber Services JUNOSe 11 0 x Broadband Access Configuration Guide...
Страница 767: ...Part 7 Index Index on page 729 Index 727...
Страница 768: ...728 Index JUNOSe 11 0 x Broadband Access Configuration Guide...