60-2
User Guide for Cisco Security Manager 4.4
OL-28826-01
Chapter 60 Router Device Administration
AAA on Cisco IOS Routers
DHCP on Cisco IOS Routers, page 60-87
DHCP Policy Page, page 60-92
NTP on Cisco IOS Routers, page 60-96
NTP Policy Page, page 60-98
AAA on Cisco IOS Routers
Authentication, authorization, and accounting (AAA) network security services provide the primary
framework through which you set up access control on your Cisco IOS router. Use the AAA policy in
Security Manager to enable AAA functionality on Cisco IOS routers and to configure default AAA
settings. The default settings that you define in this policy can be used in other policies, such as HTTP
and line access (console and VTY) policies. Enabling AAA functionality is a prerequisite for any device
policy that makes use of AAA, including NAC, SDP, and 802.1x.
For more information about AAA, see:
Supported Authorization Types, page 60-2
Supported Accounting Types, page60-3
Understanding Method Lists, page 60-3
To configure a AAA policy, see:
Defining AAA Services, page 60-4
Related Topics
Understanding AAA Server and Server Group Objects, page 6-24
Line Access on Cisco IOS Routers, page 60-35

Supported Authorization Types

AAA authorization enables you to limit the services available to an authenticated user. Security Manager
supports the following types of authorization:
Network—Authorizes various types of network connections, such as PPP, SLIP, and ARAP.
EXEC—Authorizes the launching of EXEC (CLI) sessions.
Command—Authorizes the use of all EXEC mode commands that are associated with specific
privilege levels.
When authorization is enabled, the router uses information retrieved from the user’s profile to configure
the user session. The profiles are located either in the local user database or on a security server. Users
are granted access to a requested service only if the profile allows it.
Related Topics
Supported Accounting Types, page60-3
Understanding Method Lists, page 60-3
Defining AAA Services, page 60-4
AAA on Cisco IOS Routers, page 60-2