Authentication, Authorization,
and Accounting
3.0 Introdução
3.1 Objetivo do AAA
3.2 Autenticação AAA Local
3.3 AAA baseado em servidor
3.4 Autenticação AAA baseada em servidor
3.5 Autorização e Contabilidade Baseada em Servidor
3.6 Resumo
© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 2
© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 3
Telnet is Vulnerable to Brute-Force Attacks
© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 4
SSH and Local Database Method
© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 5
© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 6
© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 7
Local AAA
Authentication
Server-Based
AAA Authentication
© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 8
AAA Authorization
© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 9
Types of accounting information:
• Network
• Connection
AAA Accounting
• EXEC
• System
• Command
• Resource
© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 10
Upon completion of this section, you should be able to:
Configure AAA authentication, using the CLI, to validate users against a local
database.
Troubleshoot AAA authentication that validates users against a local database.
© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 11
© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 12
1. Add usernames and passwords to the local router database for users
that need administrative access to the router.
2. Enable AAA globally on the router.
3. Configure AAA parameters on the router.
4. Confirm and troubleshoot the AAA configuration.
© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 13
© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 14
Example Local AAA Authentication
© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 15
Command
Syntax
Display Locked
Out Users
Show Unique
ID of a Session
© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 16
© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 17
Debug Local AAA Authentication
© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 18
Understanding Debug Output
© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 19
Upon completion of this section, you should be able to:
• Describe the benefits of server-based AAA.
• Compare the TACACS+ and RADIUS authentication protocols.
© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 20
© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 21
Local authentication:
1. O usuário estabelece uma conexão
com o roteador.
2. O roteador solicita ao usuário um
nome de usuário e senha,
autenticando o usuário usando um
banco de dados local.
Server-based authentication:
1. O usuário estabelece uma conexão
com o roteador.
2. O roteador solicita ao usuário um
nome de usuário e uma senha.
3. O roteador passa o nome de
usuário e a senha para o Cisco
Secure ACS (servidor ou
mecanismo)
4. O Cisco Secure ACS autentica o
usuário.
© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 22
© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 23
© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 24
© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 25
TACACS+ Authentication Process
© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 26
RADIUS Authentication Process
© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 27
Cisco Secure ACS
© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 28
© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 29
Upon completion of this section, you should be able to:
• Configure server-based AAA authentication, using the CLI, on Cisco
routers.
• Troubleshoot server-based AAA authentication.
© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 30
© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 31
1. Enable AAA.
2. Specify the IP address of the ACS server.
3. Configure the secret key.
4. Configure authentication to use either the RADIUS
or TACACS+ server.
© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 32
Server-Based AAA
Reference Topology
Configure a AAA
TACACS+ Server
© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 33
Configure a AAA RADIUS Server
© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 34
Command Syntax
Configure Server-Based
AAA Authentication
© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 35
© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 36
Troubleshooting Server-Based AAA
Authentication
© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 37
Troubleshooting
RADIUS
Troubleshooting TACACS+
© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 38
AAA Server-Based
Authentication
Success
AAA Server-Based
Authentication
Failure
© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 39
Upon completion of this section, you should be able to:
• Configure server-based AAA authorization.
• Configure server-based AAA accounting.
• Explain the functions of 802.1x components.
© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 40
© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 41
Authentication vs. Authorization
• Authentication garante que um dispositivo ou usuário final seja
legítimo;
• Authorization permite ou não permite que usuários autenticados
acessem determinadas áreas e programas na rede.
• TACACS+ vs. RADIUS
• TACACS+ separates authentication from authorization
• RADIUS não separa autenticação de autorização
© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 42
Command
Syntax
Authorization Method
Lists
Example AAA
Authorization
© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 43
© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 44
© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 45
Command
Syntax
Accounting Method
Lists
Example AAA
Accounting
© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 46
© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 47
802.1X Roles
802.1X Message Exchange
© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 48
Command Syntax for dot1x port-
control
© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 49
© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 50
Chapter Objectives:
• Explique como o AAA é usado para proteger uma rede.
• Implemente a autenticação AAA que valida os usuários em um banco de dados
local.
• Implemente a autenticação AAA baseada em servidor usando os protocolos
TACACS+ e RADIUS.
• Configure a autorização e a contabilidade AAA baseadas em servidor.
© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 51
Thank you.