Local Database; Tacacs+ Server - Cisco 4700M Configuration Manual

Application control engine appliance security
Hide thumbs Also See for 4700M:
Table of Contents

Advertisement

Chapter 2
Configuring Authentication and Accounting Services

Local Database

TACACS+ Server

OL-16202-01
If a dead-time interval is specified for a AAA server and the connection to server
A fails, the ACE marks server A as out of service and skips server A for the
duration of the dead-time interval. The ACE then sends probe access-request
packets to verify that the AAA server is available and can receive authentication
requests. When the server responds to a probe access-request packet, the
connection resumes to server A.
This section contains the following topics:
Local Database
TACACS+ Server
RADIUS Server
LDAP Directory Server
You can configure user account access to the local database on the ACE for
CLI access authentication. When a user attempts to access the ACE CLI by using
the console port or a Telnet or SSH session, the ACE consults the local user
database for the username and password. By default, each user assumes the
Network-Monitor role and is allowed to operate on all domains.
If you specify local authentication as the fallback method and the specified AAA
servers in a server group are unavailable for authentication, the ACE then attempts
to access the local database to perform user authentication and accounting.
TACACS+ controls user access to the ACE by exchanging Network Access Server
(NAS) information between the ACE and a centralized database to determine the
identity of a user. TACACS+ is an enhanced version of TACACS, a User
Datagram Protocol (UDP)-based access-control protocol that is specified by
RFC 1492. TACACS+ uses TCP to ensure reliable delivery and encrypt all traffic
between the TACACS+ server and the TACACS+ daemon on the ACE.
A TACACS+ server can provide user authentication and accounting functions.
These services, while all part of TACACS+, are independent of one another, so a
given TACACS+ configuration can use any or all of the services.
Cisco 4700 Series Application Control Engine Appliance Security Configuration Guide
AAA Overview
2-5

Advertisement

Table of Contents
loading

This manual is also suitable for:

4700 series

Table of Contents