Operation
is a secure, encrypted protocol. By remotely accessing servers that are provisioned
with the administrative user account database, the ASR 5000 can provide AAA services for system
administrative users. is an enhanced version of the TACACS protocol that uses TCP instead of
UDP.
The ASR 5x00 system serves as the Network Access Server (NAS). As the NAS the system
requests AAA services on behalf of authorized system administrative users. For the authentication
to succeed, the server must be in the same local context and network accessed by the system.
The system supports multiple-connection mode. In multiple-connection mode, a separate and
private TCP connection to the server is opened and maintained for each session. When the
session ends, the connection to the server is terminated.
is a system-wide function on the ASR 5x00. AAA service configuration is performed
in TACACS Configuration Mode. Enabling the function is performed in the Global Configuration
Mode. The system supports the configuration of up to three servers.
Once configured and enabled on the system, authentication is attempted first. By default, if
authentication fails, the system then attempts to authenticate the user using non- AAA
services, such as RADIUS.
For releases after 15.0 MR4,
accounting (CLI event logging) will not be generated for Lawful
Intercept users with privilege level set to 15 and 13.
Important
User Account Requirements
Before configuring AAA services, note the following server and StarOS user account
provisioning requirements.
User Account Requirements
The server must be provisioned with the following user account information:
•
A list of known administrative users.
•
The plain-text or encrypted password for each user.
•
The name of the group to which each user belongs.
•
A list of user groups.
•
privilege levels and commands that are allowed/denied for each group.
ASR 5000 System Administration Guide, StarOS Release 21.1
55
System Settings
Operation
Summary of Contents for ASR 5000
Page 26: ...ASR 5000 System Administration Guide StarOS Release 21 1 xxvi Contents ...
Page 316: ...ASR 5000 System Administration Guide StarOS Release 21 1 288 VLANs VLAN Related CLI Commands ...
Page 400: ...ASR 5000 System Administration Guide StarOS Release 21 1 372 Engineering Rules ECMP Groups ...