Implementing AAA Using External Servers


For a small organization, using the router's local database makes economic sense. However, when you have hundreds or thousands of users, that solution does not scale.

For scalability reasons, and also for centralized management, AAA often uses an external server and not the local router database. When AAA uses an external server and a user attempts to establish a connection to the properly configured router, the router issues a prompt for a username and password. However, when the user enters her username and password, the router sends a packet to the external AAA server with the user's identity credentials. It is the external AAA server that verifies whether the user passes or fails the identity check.

When the external AAA server either confirms or denies the user's identity check, it sends a packet back to the router telling the router that authentication passed or authentication failed.



CCSP SECUR Exam Cram 2
CCSP SECUR Exam Cram 2 (642-501)
ISBN: B000MU86IQ
EAN: N/A
Year: 2003
Pages: 291
Authors: Raman Sud

flylib.com © 2008-2017.
If you may any questions please contact us: flylib@qtcs.net