ZyXEL MI-7248 User Guide - Page 159

Authentication and Accounting

Page 159 highlights

CHAPTER 28 Authentication and Accounting This chapter describes how to configure authentication and accounting settings on the switch. 28.1 Authentication, Authorization and Accounting (AAA) Authentication is the process of determining who a user is and validating access to the switch. The switch can authenticate users who try to log in based on user accounts configured on the switch itself. The switch can also use an external authentication server to authenticate a large number of users Authorization is the process of determining what a user is allowed to do. Different user accounts may have higher or lower privilege levels associated with them. For example, user A may have the right to create new login accounts on the switch but user B cannot. The switch can authorize users based on user accounts configured on the switch itself or it can use an external server to authorize a large number of users. Accounting is the process of recording what a user is doing. The switch can use an external server to track when users log in, log out, execute commands and so on. Accounting can also record system related actions such as boot up and shut down times of the switch. The external servers that perform authentication, authorization and accounting functions are known as AAA servers. The switch supports RADIUS (Remote Authentication Dial-In User Service, see Section 28.1.2 on page 160) and TACACS+ (Terminal Access Controller AccessControl System Plus, see Section 28.1.2 on page 160) as external authentication, authorization and accounting servers. Figure 69 AAA Server Client AAA Server 28.1.1 Local User Accounts By storing user profiles locally on the switch, your switch is able to authenticate and authorize users without interacting with a network AAA server. However, there is a limit on the number of users you may authenticate in this way (See Chapter 33 on page 271). MS-7206 User's Guide 159

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310

MS-7206 User’s Guide
159
C
HAPTER
28
Authentication and Accounting
This chapter describes how to configure authentication and accounting settings on the switch.
28.1
Authentication, Authorization and Accounting (AAA)
Authentication is the process of determining who a user is and validating access to the switch.
The switch can authenticate users who try to log in based on user accounts configured on the
switch itself. The switch can also use an external authentication server to authenticate a large
number of users
Authorization is the process of determining what a user is allowed to do. Different user
accounts may have higher or lower privilege levels associated with them. For example, user A
may have the right to create new login accounts on the switch but user B cannot. The switch
can authorize users based on user accounts configured on the switch itself or it can use an
external server to authorize a large number of users.
Accounting is the process of recording what a user is doing. The switch can use an external
server to track when users log in, log out, execute commands and so on. Accounting can also
record system related actions such as boot up and shut down times of the switch.
The external servers that perform authentication, authorization and accounting functions are
known as AAA servers. The switch supports RADIUS (Remote Authentication Dial-In User
Service, see
Section 28.1.2 on page 160
) and TACACS+ (Terminal Access Controller Access-
Control System Plus, see
Section 28.1.2 on page 160
) as external authentication, authorization
and accounting servers.
Figure 69
AAA Server
28.1.1
Local User Accounts
By storing user profiles locally on the switch, your switch is able to authenticate and authorize
users without interacting with a network AAA server. However, there is a limit on the number
of users you may authenticate in this way (See
Chapter 33 on page 271
).
Client
AAA Server