Introduction and Features

Introduction and Features

Cisco Secure ACS for Windows is AAA server software that provides centralized

user authentication, authorization, and accounting for arrangement accessories that act as

AAA clients, such as routers, NASs,VPN gateways, wireless admission points, and

firewalls. It accompanying supports both the TACACS+ and RADIUS protocols,

allowing you to use the agreement that is best adapted for anniversary client. For

instance, you could use TACACS+ command allotment for routers and firewalls

and use RADIUS affidavit for VPN access.

Cisco Secure ACS is additionally awful scalable, accouterment abutment for up to 500,000

users and 2000 AAA clients. An AAA server such as Cisco Secure ACS can

quickly become a analytical allotment of your infrastructure.To ensure the availability of

AAA services, Cisco Secure ACS supports database archetype to added ACS

servers. If one server goes down, others are accessible to accommodate AAA services

with accepted information.You can carbon all or genitalia of the database and

can configure archetype to be performed automatically at specific times (for

example, every 60 minutes) or manually. For beyond implementations, you can also

configure a bureaucracy of servers for which archetype to accessory servers is initiated

when a primary server completes its replication. Cisco Secure ACS provides

a Web-based graphical interface, giving you the adaptability of managing the server

remotely.Through the ACS interface, you can ascertain users, groups of users,AAA

clients, and alien affidavit databases.While Cisco Secure ACS includes

its own centralized user database, it additionally supports affidavit adjoin the following

external user databases:

 Windows NT/2000 User Database

 Generic LDAP

 Novell NetWare Directory Casework (NDS)

 Open Database Connectivity (ODBC) adjustable relational databases

 CRYPTOCard badge server

 SafeWord badge server

www.syngress.com

230 Chapter 5 • Authentication, Authorization, and Accounting

 AXENT badge server

 RSA SecureID badge server

 ActivCard badge server

 Vasco badge server

Cisco Secure ACS for Windows

Cisco Secure ACS for Windows

You now accept a basal compassionate of AAA functions and the best commonly

implemented protocols (TACACS+ and RADIUS). In adjustment to apparatus AAA

services on the PIX firewall, you charge to apparatus and configure an AAA

server. Many AAA server articles are available; the PIX firewall provides support

for the following:

 Cisco Secure ACS for Windows

 Cisco Secure ACS for UNIX

 Livingston

 Merit

This affiliate concentrates on Cisco Secure Access Control Server (ACS) for

Windows 3.0.2 by anecdotic its features, how to install and configure it, and

how to accomplish basal tasks such as abacus AAA audience and users.

Security Agreement Considerations

Security Agreement Considerations

Selecting a aegis agreement can be a alarming assignment for administrators.

Many factors charge be taken into consideration. For example, will this

security agreement facilitate alone Cisco routers? Should one or two servers

be committed in case of failure? Is one agreement easier to configure than

the others?

The two best broadly acclimated aegis protocols are RADIUS and

TACACS+. Which one should be implemented in your enterprise?

Several factors will access your decision:

 Vendor interoperability RADIUS enjoys abutment from more

vendors than TACACS+.

 Transport agreement considerations RADIUS uses UDP as the

transport band protocol, admitting TACACS+ uses TCP, making

RADIUS the faster adjustment of the two, back UDP has less

overhead. What this agency is that TACACS+ cartage is more

reliable than RADIUS traffic. If any disruption occurs (such as

corrupted or alone packets), TACACS+ will retransmit

unacknowledged packets, admitting RADIUS will not.

 Packet encryption RADIUS alone encrypts the countersign portion

of the access-request packet from the AAA applicant to the

AAA server. The blow of the packet is beatific in bright text, which

can be captured and beheld by a arrangement or agreement analyzer.

TACACS+ encrypts the absolute anatomy of the packet except

the TACACS+ header.

 Aerial RADIUS uses beneath CPU aerial and consumes

less anamnesis than TACACS+.

 Affidavit and allotment RADIUS combines

authentication and authorization. The access-accept packets

exchanged by the RADIUS applicant and the server contain

authorization information. This makes it difficult to separate

the two elements. TACACS+ separates authentication, authorization,

and accounting, acceptance for advantages such as

multiprotocol use. For example, TACACS+ could accommodate the

authorization and accounting elements, and Kerberos may be

used for the allotment element.

 Agreement abutment RADIUS does not abutment the following

protocols, but TACACS+ does:

 AppleTalk Remote Access (ARA) protocol

 NetBIOS Frame Agreement Control protocol

 Novell Asynchronous Casework Interface (NASI)

 X.25 PAD connection

It is additionally important to accept that assertive appearance in anniversary AAA

client will alone assignment with one of the protocols (RADIUS, or TACACS+)

and not the other. For example, the PIX firewall alone supports TACACS+

for allotment casework and alone supports RADIUS for downloadable

access lists.

A abundant allegory of RADIUS and TACACS+ is accessible at

www.cisco.com/warp/public/480/10.html.

TACACS+

TACACS+

Another aegis agreement that is accessible is Terminal Admission Controller Access

Control System Plus (TACACS+).This should not be abashed with TACACS

and XTACACS, both of which are accessible accepted protocols accurate in RFC

1492 and no best used. Despite the agnate names,TACACS and XTACACS

are not accordant with TACACS+.TACACS+ provides a adjustment to validate

users attempting to accretion admission to a account through a router or NAS. Agnate to

RADIUS, a centralized server active TACACS+ software responds to client

requests in adjustment to accomplish AAA.

NOTE

Although the blueprint for TACACS+ was never appear as a final

standards document, a abstract of the blueprint is accessible at

ftp://ftpeng.cisco.com/pub/tacacs/tac-rfc.1.78.txt.

TACACS+ packets await on TCP as the carriage protocol, authoritative the

connection reliable.TACACS+ can additionally encrypt the anatomy of cartage travelling

www.syngress.com

226 Chapter 5 • Authentication, Authorization, and Accounting

between the TACACS+ server and client. Only the packet attack is larboard unencrypted.

TACACS+ allows an ambassador to abstracted the authentication, authorization,

and accounting mechanisms, thereby accouterment the adeptness to implement

each account independently. Each of the AAA mechanisms can be angry into separate

databases.TACACS+ uses TCP anchorage 49 for communication.

Figure 5.3 illustrates the action that occurs aback a user attempts to log in by

authentication to a NAS application TACACS+:

1. Aback the affiliation is established, the NAS contacts the TACACS+

server to admission an affidavit prompt, which is again displayed to the

user.The user enters his or her username, and the NAS again contacts

the TACACS+ server to admission a countersign prompt.The NAS displays

the countersign alert to the user.

2. The user enters his or her password, and these accreditation are again sent

to the TACACS+ apparition active on a server.

3. The TACACS+ server queries the user database and compares Applicant A’s

credentials with those stored in the database server.

4. The NAS will eventually accept one of the afterward responses from

the TACACS+ daemon:

www.syngress.com

Figure 5.3 Acceptance with TACACS+

Database

Server

Client A Modem

Network

Access

Server

TACACS+

Server

Server Farm

1. Applicant A dials into the NAS and is

prompted for login and password.

Remote Access

Client

2. The NAS queries the

TACACS+ server to

authenticate Applicant A.

3. The TACACS+ server

queries the database

where user account

definitions are stored.

4. Accreditation are validated,

an ACCEPT bulletin is

sent aback to the NAS, and

access is granted.

PSTN

Authentication, Authorization, and Accounting • Chapter 5 227

 ACCEPT The user is accurate and the account can begin.

 REJECT The user bootless authentication. Depending on the

TACACS+ daemon, the user may be denied added admission or

prompted to retry the login sequence.

 ERROR An absurdity occurred at some point during the authentication

process.This can be either at the apparition or in the network

connection amid the apparition and the NAS. If an ERROR

response is received, the NAS will about try to use an alternative

method for acceptance the user.

 CONTINUE The user is prompted for added authentication

information.

RADIUS cisco

RADIUS

The Alien Admission Dial In User Service (RADIUS) agreement was developed by

Livingston Enterprises, Inc., as an admission server affidavit and accounting

protocol. Although abounding RFCs are accessible on RADIUS, the capital specification

can be begin in RFC 2058, which was fabricated anachronistic by RFC 2865.The

RADIUS accounting accepted is accurate in RFC 2059, which was made

obsolete by RFC 2866.

RADIUS can be acclimated as a aegis agreement for a arrangement of any size, from

large action networks such as ISPs to baby networks consisting of a few users

requiring alien access. RADIUS is a client/server protocol.The RADIUS

client is about a NAS, firewall, router, or VPN gateway, which requests a service

such as affidavit or allotment from the RADIUS server.A

www.syngress.com

224 Chapter 5 • Authentication, Authorization, and Accounting

RADIUS server is usually a apparition active on a UNIX apparatus or a service

running on a Windows NT/2000 server.The apparition is software such as Cisco

Secure ACS or addition RADIUS server affairs that fulfills requests from

RADIUS clients. Originally, RADIUS acclimated UDP anchorage 1645 for authentication

traffic and 1646 for accounting traffic. However, due to an blank in the standardization

process, these ports were registered with the IANA to altered services.

To get about this issue, new anchorage numbers were assigned to the RADIUS

services (1812 for affidavit and 1813 for accounting). However, many

RADIUS implementations still use the old anchorage numbers.

When a applicant needs allotment information, it passes the user credentials

to the appointed RADIUS server and queries it.The server again acts on the

configuration advice all-important for the applicant to bear casework to the user.

A RADIUS server can additionally act as a proxy applicant to added RADIUS servers.

Figure 5.2 illustrates what happens aback a user attempts to log in and authenticate

to a NAS application RADIUS.

The arrangement of contest is as follows:

1. The alien user dials into a NAS and is prompted by the NAS for

credentials such as a username and password.

www.syngress.com

Figure 5.2 Authenticating with RADIUS

Database

Server

Client A Modem

Network

Access

Server

RADIUS

Server

Server Farm

1. Applicant A dials into the NAS and is

prompted for login and password.

Remote Access

Client

2. The NAS queries the

RADIUS server to

authenticate Applicant A.

3. The RADIUS server

queries the database

where user account

definitions are stored.

4. Accreditation are validated,

an ACCEPT bulletin is

sent aback to the NAS, and

access is granted.

PSTN

Authentication, Authorization, and Accounting • Chapter 5 225

2. The username and encrypted countersign are beatific from the RADIUS

client (NAS) to the RADIUS server via the network.

3. The RADIUS server queries the database in which user annual definitions

are stored.

4. The RADIUS server evaluates the accreditation and replies with one of

the afterward responses:

 REJECT The user is not authenticated; the user is prompted to reenter

the username and password. Depending on the RADIUS configuration,

the user is accustomed a assertive cardinal of tries afore user

access is denied.

 ACCEPT The user is authenticated.

 CHALLENGE A claiming is issued by the RADIUS server, with

a appeal for added advice from the user.

 CHANGE PASSWORD A appeal is beatific from the RADIUS

server allegorical that the user charge change his or her current

password.