Version 6.6
375
October 2014
Installation & Operation Manual
33. Configuring Security Settings
33.18.6
Centralized AAA Servers
In large scale deployments, centralized Authentication, Authorization and Accounting
(AAA) servers are used to control user access to different network equipment. AAA
servers implement the following functionality:
Authenticate user login to the specific equipment.
Authorize certain tasks or commands that specific users may perform on specific
equipment.
Report which users are accounted for which tasks on the specific equipment.
Use of the AAA servers allows use of the same user credentials (usernames and
passwords) across multiple network equipment. It also greatly simplifies user
provisioning and may be used to enforce enhanced security policies, for example:
Time-based login
Enforce password complexity
Immediately revoke privileges from specific users The Mediant 8000 supports two
types of centralized AAA servers:
Servers
RADIUS Servers
When the Mediant 8000 is configured to work with centralized AAA servers, all user
maintenance and provisioning tasks should be performed on the AAA servers (using
the corresponding configuration interfaces) and not via the
tools user
or
passwd
CLI
commands.
33.18.6.1
Centralized Servers
Terminal Access Controller Access-Control System Plus () is a AAA
protocol developed by Cisco and supported by most Cisco network equipment.
servers provide all AAA services – authentication, authorization and
accounting – thus greatly simplifying network administration and user management.
Multiple servers may be deployed for high-available network setups.
The Mediant 8000 supports interworking with standard-compliant servers
and implements all AAA services as defined by the protocol (see details below). Up to
three servers may be defined for redundancy purposes. Local user cache
is implemented for emergency access to the Mediant 8000 in case of network outage
(for more information, see Section ' Protocol Overview' below).
33.18.6.1.1 Protocol Overview
The Mediant 8000 implements the latest version of the protocol as defined
in IETF draft-grant-tacacs-02. All major protocol functionality, including message
encryption, is supported.
Up to three servers may be configured for redundancy purposes. The
Mediant 8000 falls back to the redundant server in case communication
with the active server fails. Communication with the currently selected
server continues until the next failure.
Summary of Contents for Mediant 8000
Page 2: ......
Page 33: ...Part I Hardware Overview This part describes the hardware overview of the Mediant 8000 chassis...
Page 34: ......
Page 90: ......
Page 158: ......
Page 264: ......
Page 546: ......
Page 775: ...Part VI Maintenance This part describes the Mediant 8000 maintenance procedures...
Page 776: ......
Page 834: ......
Page 879: ...Part VIII Appendices This part describes additional Mediant 8000 configuration procedures...
Page 880: ......
Page 924: ...Media Gateway Mediant 8000 www audiocodes com Installation Operation Maintenance Manual...