User's Manual

User Manual
79
6.5 AAA
AAA is a security management mechanism for access control in network
security, which provides three security services: authentication, authorization,
and accounting.
● Authentication: Verify whether a user has the right to access.
● Authorization: Authorize a user to use specific services.
● Accounting: Record a user’s network resource usage.
You can use only one or two of the security services provided by AAA. For
example, if a company only expects to authenticate employees when they
access to specific resources, the network administrator only needs to configure
the authentication server. However, if a company expects to record the network
usage of employees, the accounting server must be configured.
AAA usually works in client/server structure, which is highly scalable and
convenient for centralized management of user information. as shown in the
figure below.
Note: RadiusTacacs+ and LDAP indicate authentication and authorization
servers. Local indicates the local user name and password of the router.