Section 3, Common Provisioning - Provision Authentication, Authorization, and Accounting (AAA)
65K510DEP08-1A 3-19
View SNTP
FromtheEnableprompt,typeshow sntp,andpressENTERtoviewtheSNTPstatus.
Provision Authentication, Authorization, and Accounting
(AAA)
AAAcontainsthefollowingthreeelements:
• Authenticationistheprocessofloggingintothe networkelement.Uponenteringa
usernameandpassword,thelocalaccountdatabaseortheTACACS+and/orRADIUS
serversdetermineifthelogonattemptissuccessfulforthegivenuser.
• CommandAuthorizationprovidesaprocesstoallowa
TACACS+servertograntordeny
accesstoauseronaper‐commandbasis.WhenauserentersaCLIcommand,butbefore
thecommandisexecuted,aTACACS+serverisqueriedtodetermineifthecommandcan
beexecutedbythatuser.
• CommandAccountingistheprocessofnotifying
aTACACS+serverwhentheuserenters
aCLIcommand.ItallowstheTACACS+servertomaintainlogsofCLIcommandactivity
foreachuser.
IfusingTACACS+forauthentication,thenauthorizationand/oraccountingcanoptionallybe
enabledordisabled.TheexecutableCLIcommandsdependonwhethercommandauthori‐
zation
isenabledordisabled.
Forauthentication,bothRADIUSandTACACS+ canreturnaresponsethatrequestsmore
informationfromtheuser(suchasachallengequestion),inwhichcasetheproductdisplays
themessagefromtheservertotheuser,andawaitsinputfromtheuser.Multiplecha llenge
transactionscanbe
madeduringanauthenticationrequest.
Authenticationalsooccurswhentheuserenters
enablefromtheEnableprompt.If
TA CACS+iscontainedintheauthenticationloginmethodlist,thenuponentering
enable
fromtheEnableprompt,theproducttransmitsanotherauthenticationrequesttothe
TA CACS+server.Aswithlogin,theservercanrespondwithamessagerequestingmoreinfor‐
mation,suchasapassword.Successfulauthenticationinthisprocessresultsintheuserbeing
escalatedinprivilegelevel,andgrantedaccessto
theEnableprompt.
WhenauserattemptstoaccesstheTotalAccess5000,theTotalAccess5000connectstothe
TA CACS+orRADIUSservertoverifythe userandwhattheusercando.TheTotalAccess
5000mustbeconfiguredtotalktothecorrectserver,alongwiththeactions
totakeiftheserver
cannotbecontacted.
Configure TACACS+ Server(s)
TouseaTACACS+server,theserverparametersmustbeconfiguredintheTotalAccess5000
sothattheTotalAccess5000cancommunicatewiththeserver.
TheTotalAccess5000supportsupto4TACACS+serversconfiguredinasingledefaultgroup.
Theserverscontainasequencenumberthatgoverns
theorderinwhichcommunicationis
attempted.Whenaserverisaddedtothesystem,itisenteredintothedefaultTACACS+
serverlistasthenextavailableserverafteranyexistingservers.Aserver’ssequencenumber
canbemodified.Aserverhavingasequencenumberofzeroisneverqueried.
ToconfigureaTACACS+server,completethefollowingprocedure:
1. FromtheEnableprompt,type
configure terminal,andpressENTERtoaccesstheGlo‐
balConfigurationprompt.