AAA Authentication Setup with TACACS+ and RADIUS

To authenticate large numbers of users, you need to have a database that stores the usernames and passwords. This is where either TACACS+ or RADIUS servers come into play.

On the router configuration, TACACS+ and RADIUS are not difficult to configure. They also allow for multiple forms of authentication, including:

  • Digital certificates

  • One-time passwords

  • Changeable passwords

  • Static passwords

  • UNIX authentication using the /etc/password file

  • NT database authentication

Three steps are required to make a router use AAA:

Step 1.
Initial configuration
Step 2.
Building a method list
Step 3.
Linking the list to interfaces

Each of these will be discussed in turn.

Initial Configuration

You need to know a ...

Get Cisco® Secure Internet Security Solutions now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.