Anda di halaman 1dari 54

Chapter 3:

Authentication, Authorization,
and Accounting (AAA)

CCNA Security v2.0


3.0 Introduction

3.1 Purpose of the AAA

3.2 Local AAA Authentication

3.3 Server-Based AAA

3.4 Server-Based AAA Authentication

3.5 Server-Based Authorization and Accounting

3.6 Summary

© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 2
Al terminar esta seccion estaras habilitado para:
• Explicar por que AAA es fundamental para la seguridad de la red.

• Describir las caracteristicas de AAA.

© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 3
© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 4
Telnet es Vulnerable a ataques de fuerza bruta
(Brute-Force Attacks)

© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 5
Los metodos habituales son el SSH y la base
de datos local

© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 6
© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 7
© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 8
Autenticacion
AAA Local

Autenticacion AAA
Basada en servidor

© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 9
AAA Authorization

© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 10
Tipos de informacion de Accounting(registro):
• Network

• Connection

• EXEC AAA Accounting


• System

• Command

• Resource

© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 11
Al acabar esta seccion estara habilitado para:
• Configurar AAA authentication, usando CLI, para validar usuarios en la base de
datos local
• Solucionar problemas de autenticacion AAA que validen usuarios en la base de
datos local.

© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 12
© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 13
1. Añadir usuarios y contraseñasAdd usernames and passwords to the local
router database for users that need administrative access to the router.
2. Habilitar AAA globalmente en el router.
3. Configurar en el router los parametros AAA.
4. Verificar y solucionar problemas en la configuracion AAA.

© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 14
© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 15
Example Local AAA Authentication

© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 16
Sintaxis del
comando

Visualizar
usuarios
bloqueados

Visualizar
identificador
unico de sesion

© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 17
© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 18
Debug Local AAA Authentication

© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 19
Understanding Debug Output

© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 20
Al finalizar esta seccion usted podra:
• Describir los beneficios de AAA basado en servidor.

• Comparar los protocolos de autenticacion TACACS+ y RADIUS.

© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 21
© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 22
Autenticacion local:

1. El usuario establece una


conexion con el router.

2. El router solicita usuario y


contraseña y la compara conla
base de datos local .

Autenticacion basada en servidor:

1. El usuario establece una


conexion con el router.

2. El router solicita usuario y


contraseña

3. El router le pasa el usuario y la


contraseña.El Router le pasa le
contraseña y el usuario al ACS
(Access Control server) (servidor
o motor)

4. El Cisco Secure ACS autentica al


usuario.

© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 23
© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 24
© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 25
© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 26
TACACS+ Authentication Process

© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 27
RADIUS Authentication Process

© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 28
Cisco Secure ACS

© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 29
© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 30
Al acabar esta seccion estara habilitado para:
• Configurar autenticacion AAA basada en servidor, usando CLI en Routers Cisco.

• Resolucion de problemas de autenticacion basado en servidor.

© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 31
© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 32
1. Habilitar AAA.
2. Especificar la IP del servidor ACS.
3. Configurar la clave secreta.
4. Configurar la autenticacion para utilizer o bien un servidor
RADIUS o bien un servidor TACACS + .

© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 33
Topologia de referencia
de servidor AAA
basada en servidor

Configuracion de
AAA TACACS+
Server

© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 34
Configure a AAA RADIUS Server

© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 35
Sintaxis del
comando

Configuracion de
autenticacion AAA
basada en servidor

© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 36
© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 37
Troubleshooting Server-Based AAA Authentication

© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 38
Troubleshooting RADIUS

Troubleshooting TACACS+

© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 39
AAA Server-Based
Authentication Success

AAA Server-Based
Authentication Failure

© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 40
Al completer esta seccion usted podrá:
• Configurar la autorizacion AAA basada en servidor.

• Configurar accounting AAA basada en servidor.

• Explicar las funciones de los componentes 802.1x .

© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 41
© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 42
Autenticacion vs. Autorizatcion
• Autenticacion: garantiza que un dispositivo o un usuario final es legitimo
• Authorization Permite o deniega a usuarios autenticados a accede a ciertas
y programas en la red.

TACACS+ vs. RADIUS


• TACACS+ : separa autenticacion de autorizacion
• RADIUS : no separa autenticacion de autorizacion

© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 43
Command Syntax

Authorization Method Lists

Example AAA Authorization

© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 44
© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 45
© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 46
Command Syntax

Accounting Method Lists

Example AAA Accounting

© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 47
© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 48
802.1X Roles

802.1X Message Exchange

© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 49
Syntaxis del Comando para el control de puerto dot1x

© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 50
© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 51
Chapter Objectives:
• Explain how AAA is used to secure a network.

• Implement AAA authentication that validates users against a local database.

• Implement server-based AAA authentication using TACACS+ and RADIUS


protocols.
• Configure server-based AAA authorization and accounting.

© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 52
Thank you.
• Remember, there are
helpful tutorials and user
guides available via your
NetSpace home page. 1
(https://www.netacad.com) 2
• These resources cover a
variety of topics including
navigation, assessments,
and assignments.
• A screenshot has been
provided here highlighting
the tutorials related to
activating exams, managing
assessments, and creating
quizzes.

© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 54

Anda mungkin juga menyukai