Which protocol is commonly used for centralized authentication, authorization, and accounting in network devices?

Optimize your success on the FSNA Readiness Exam. Engage with flashcards and multiple choice questions, each designed with hints and explanations. Prepare thoroughly for your test and excel!

Multiple Choice

Which protocol is commonly used for centralized authentication, authorization, and accounting in network devices?

Explanation:
Centralized authentication, authorization, and accounting on network devices relies on a protocol designed to manage all three functions from a central server. TACACS+ fits this role best because it separates authentication, authorization, and accounting, allowing a central policy to govern who can access a device, what commands they’re permitted to run, and what actions they perform. It also encrypts the entire payload between the device and the AAA server, enhancing security for credentials and authorization data, and it uses TCP for reliable transport between devices and the management server. RADIUS can centralize AAA as well, but it’s more commonly used for authentication and accounting for remote access scenarios, with less flexible, finer-grained command authorization and, traditionally, encryption that doesn’t cover the whole payload. LDAP is a directory service used to look up user information, not a protocol for managing device-level AAA across multiple network devices. SSH is a secure remote access method, not a centralized AAA protocol. So, for centralized AAA on network devices, TACACS+ is the most appropriate choice.

Centralized authentication, authorization, and accounting on network devices relies on a protocol designed to manage all three functions from a central server. TACACS+ fits this role best because it separates authentication, authorization, and accounting, allowing a central policy to govern who can access a device, what commands they’re permitted to run, and what actions they perform. It also encrypts the entire payload between the device and the AAA server, enhancing security for credentials and authorization data, and it uses TCP for reliable transport between devices and the management server.

RADIUS can centralize AAA as well, but it’s more commonly used for authentication and accounting for remote access scenarios, with less flexible, finer-grained command authorization and, traditionally, encryption that doesn’t cover the whole payload. LDAP is a directory service used to look up user information, not a protocol for managing device-level AAA across multiple network devices. SSH is a secure remote access method, not a centralized AAA protocol.

So, for centralized AAA on network devices, TACACS+ is the most appropriate choice.

Subscribe

Get the latest from Passetra

You can unsubscribe at any time. Read our privacy policy