AAA Servers

Authentication, authorization, and accounting (AAA) is a set of services to regulate access to system resources, enforce privilege policies, and assess usage. These processes ensure effective network management and security. The AAA server is a network server that is used for access control which handles user requests for access to computer resources and provides AAA services: authentication, authorization, and accounting.

You can configure the following servers to provide AAA services:

  • RADIUS
  • TACACS+
You can specify up to eight RADIUS servers and eight TACACS+ servers. If you add multiple AAA servers to the device, the device tries to reach them in the order they are added.

Local User Accounts

User accounts regulate who can access the management functions. You can create accounts for local users with passwords for authentication purposes which are stored in a local database. You can use a local database instead of AAA servers to provide user authentication. You can also specify various privilege levels of access for users. Up to 32 local user accounts can be defined on a RUCKUS device. When a user tries to gain access to the device, the authentication credentials are verified against the user credentials stored in the database.

Specifying Different Servers for Individual AAA Functions

Separate RADIUS and TACACS+ servers can be configured and assigned for specific AAA tasks. For example, you can designate one RADIUS or TACACS+ server to handle authentication and another RADIUS or TACACS+ server to handle accounting. You can specify individual servers for authentication and accounting, but not for authorization. By default, RADIUS and TACACS+ servers perform all AAA functions. After authentication takes place, the server that performed authentication is used for authorization and accounting. If the authenticating server cannot perform the requested function, the next server in the configured list of servers is tried. This process repeats until a server that can perform the requested function is found or until every server in the configured list has been tried.

Authentication

Authentication is a means to identify a user by verifying the authentication credentials before access is granted. The AAA server compares the username and password entered by the user with other login credentials stored in a database. If the credentials match, the user is granted access to the network.

Authorization

Authorization is a method of setting control on the privilege level for the user after authentication. The amount of information and the amount of services the user has access to depend on the authorization level of the user. The authorization level largely determines what types of activities a user can perform and the management commands that an authenticated user is authorized to use.

Accounting

Accounting records and measures the information about user activity and system events such as when a user logs in to the device or the system is rebooted. Accounting information includes session start and stop time, the amount of system time, the services accessed, and the amount of data that a user has sent or received during a session.

If authorization is enabled and a command requires authorization, authorization is performed before accounting takes place. If authorization fails for the command, no accounting takes place. You can use authentication alone or with authorization and accounting. Authorization always requires a user to be authenticated first. You can use accounting alone, or with authentication and authorization.