ESR series service routers.ESR-Series. User manual
•
•
•
•
•
•
•
•
•
•
•
•
•
•
•
•
•
•
•
•
•
•
•
•
•
•
•
•
•
•
•
•
•
•
•
•
•
•
•
•
•
•
13 Security management
AAA configuration
Local authentication configuration algorithm
AAA configuration algorithm via RADIUS
AAA configuration algorithm via TACACS
AAA configuration algorithm via LDAP
Example of authentication configuration using telnet via RADIUS server
Command privilege configuration
Configuration algorithm
Example of command privilege configuration
Logging and network attacksprotection configuration
Configuration algorithm
Description of attack protection mechanisms
Configuration example of logging and protection against network attacks
Firewall configuration
Configuration algorithm
The order of traffic processing by firewall rules
Firewall configuration example
Configuration example of application filtering (DPI)
Access list (ACL) configuration
Configuration algorithm
Access list configuration example
IPS/IDS configuration
Base configuration algorithm
Configuration algorithm for IPS/IDS rules autoupdate from external sources
Recommended open rule update source
IPS/IDS configuration example with rules autoupdate
Basic user rules configuration algorithm
Basic user rules configuration example
Extended user rules configuration algorithm
Extended user rules configuration example
Eltex Distribution Manager interaction configuration
Basic configuration algorithm
Configuration example
Content filtering service configuration
Basic configuration algorithm
Content filtering rules configuration example
Antispam service configuration
Basic configuration algorithm
Configuration example
13.1 AAA configuration
AAA (Authentication, Authorization, Accounting) is used for description of access provisioning and control.
Authentication is a matching of a person (request) for the existing account in the security system.
Performed by the login and password.
Authorization (authorization, privilege verification, access level verification) is a matching of the existing
account in the system (passed authentication) and specific privileges.
Accounting (accounting) is a monitoring of user connection or changes made by the user.