
Server
Managing Authentication Servers
page 29-12
OmniSwitch AOS Release 7 Network Configuration Guide
June 2013
Server
Terminal Access Controller Access Control System () is a standard authentication and account-
ing protocol defined in RFC 1321 that employs TCP for reliable transport. A built-in client is
available in the switch. A server allows access control for routers, network access servers, and
other networked devices through one or more centralized servers. The protocol also allows separate
authentication, authorization, and accounting services. By allowing arbitrary length and content authenti-
cation exchanges, it allows clients to use any authentication mechanism.
The client offers the ability to configure multiple servers. This can be done by the
user. When the primary server fails, the client tries the subsequent servers. Multiple server configurations
are applicable only for backup and not for server chaining.
In the protocol, the client queries the server by sending requests. The
server responds with reply packets indicating the status of the request.
•
Authentication.
protocol provides authentication between the client and the server. It also
ensures confidentiality because all the exchanges are encrypted. The protocol supports fixed pass-
words, one-time passwords, and challenge-response queries. Authentication is not a mandatory feature,
and it can be enabled without authorization and accounting. During authentication if a user is not found
on the primary server, the authentication fails. The client does not try to authenticate with
the other servers in a multiple server configuration. If the authentication succeeds, then Authorization
is performed.
•
Authorization.
Enabling authorization determines if the user has the authority to execute a specified
command. authorization cannot be enabled independently. The authorization is
enabled automatically when the authentication is enabled.
•
Accounting.
The process of recording what the user is attempting to do or what the user has done is
Accounting.
The accounting must be enabled on the switches for accounting to succeed.
Accounting can be enabled irrespective of authentication and authorization. supports three
types of accounting:
Start Records
—Indicate the service is about to begin.
Stop Records—
Indicates the services has just terminated.
Update Records—
Indicates the services are still being performed.
Client Limitations
The following limitation apply to this implementation of the client application:
•
supports Authenticated Switch Access and cannot be used for user authentication.
•
Authentication and Authorization are combined together and cannot be performed independently.
•
On the fly, command authorization is not supported. Authorization is similar to the AOS partition
management families.
•
Only inbound ASCII logins are supported.
•
A maximum of 50 simultaneous sessions can be supported when no other authentication
mechanism is activated.
•
Accounting of commands performed by the user on the remote process is not supported in
the
boot.cfg
file at boot up time.
Содержание os6900
Страница 28: ...Contents xxviii OmniSwitch AOS Release 7 Network Configuration Guide June 2013...
Страница 374: ...VRF Route Leak Configuring IP page 15 40 OmniSwitch AOS Release 7 Network Configuration Guide June 2013...
Страница 692: ...Policy Applications Configuring QoS page 25 84 OmniSwitch AOS Release 7 Network Configuration Guide June 2013...