Dell PowerConnect W Clearpass 100 Software Implementing Accounting-Based Autho - Page 6

About Accounting-Based Authorization

Page 6 highlights

2 About Accounting-Based Authorization This section provides background information explaining the concepts of authorization and accounting, and how these can interact to provide a restricted network service to guests. Authentication, Authorization and Accounting The Amigopod Visitor Management Appliance is built on the industry standard AAA framework, which consists of authentication, authorization and accounting components. Diagram 1 shows how the different components of this framework are employed in a guest access scenario. Guest NAS Amigopod VMA Associates [1] Redirects Complete login form Automated NAS login Internet browsing Unregistered role Browse to Landing page [2] Submit form [3] Login Message page [4] Access-Request [5] Access-Accept [6] Guest role [7] Accounting-Request [8] Accounting-Response Web login Authentication Authorization Accounting Session timeout [9] Accounting-Request [10] Accounting-Response Accounting States: Unauthorized Authenticating Diagram 1: Sequence diagram for network access using AAA Authorized 6| Implementing Accounting-Based Authorization Amigopod |Technical Note

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22

6
| Implementing Accounting-Based Authorization
Amigopod
|Technical Note
2
About Accounting-Based Authorization
This section provides background information explaining the concepts of authorization
and accounting, and how these can interact to provide a restricted network service to
guests.
Authentication, Authorization and Accounting
The Amigopod Visitor Management Appliance is built on the industry standard AAA
framework, which consists of authentication, authorization and accounting components.
Diagram 1 shows how the different components of this framework are employed in a guest
access scenario.
Diagram 1: Sequence diagram for network access using AAA
Guest
NAS
Amigopod VMA
Associates
[1]
Redirects
Browse to Landing page
[2]
Submit form
[3]
Login Message page
[4]
Web login
Automated NAS login
Internet browsing
Complete login form
Unregistered role
Guest role
[7]
States:
Unauthorized
Authenticating
Authorized
Access-Request
[5]
Access-Accept
[6]
Authentication
Authorization
Accounting-Request
[8]
Accounting-Response
Accounting
Session timeout
[9]
Accounting-Request
[10]
Accounting-Response
Accounting