Nortel Networks 42C4911 manual How TACACS+ Authentication Works

Models: 42C4911

1 260
Download 260 pages 54.2 Kb
Page 48
Image 48

Alteon OS Application Guide

TACACS+ Authentication

Alteon OS supports authentication and authorization with networks using the Cisco Systems TACACS+ protocol. The GbE Switch Module functions as the Network Access Server (NAS) by interacting with the remote client and initiating authentication and authorization sessions with the TACACS+ access server. The remote user is defined as someone requiring manage- ment access to the GbE Switch Module either through a data or management port.

TACACS+ offers the following advantages over RADIUS:

„TACACS+ uses TCP-based connection-oriented transport; whereas RADIUS is UDP- based. TCP offers a connection-oriented transport, while UDP offers best-effort delivery. RADIUS requires additional programmable variables such as re-transmit attempts and time-outs to compensate for best-effort transport, but it lacks the level of built-in support that a TCP transport offers.

„TACACS+ offers full packet encryption whereas RADIUS offers password-only encryp- tion in authentication requests.

„TACACS+ separates authentication, authorization and accounting.

How TACACS+ Authentication Works

TACACS+ works much in the same way as RADIUS authentication as described on page 44.

1.Remote administrator connects to the switch and provides user name and password.

2.Using Authentication/Authorization protocol, the switch sends request to authentication server.

3.Authentication server checks the request against the user ID database.

4.Using TACACS+ protocol, the authentication server instructs the switch to grant or deny administrative access.

During a session, if additional authorization checking is needed, the switch checks with a TACACS+ server to determine if the user is granted permission to use a particular command.

TACACS+ Authentication Features in Alteon OS

Authentication is the action of determining the identity of a user, and is generally done when the user first attempts to log in to a device or gain access to its services. Alteon OS supports ASCII inbound login to the device. PAP, CHAP and ARAP login methods, TACACS+ change password requests, and one-time password authentication are not supported.

48 „ Chapter 1: Accessing the Switch

42C4911, January 2007

Page 48
Image 48
Nortel Networks 42C4911 manual How TACACS+ Authentication Works, TACACS+ Authentication Features in Alteon OS

42C4911 specifications

Nortel Networks 42C4911 is a key hardware component designed to meet the needs of modern telecommunications infrastructure. As part of Nortel's extensive portfolio, the 42C4911 has made a significant impact on network design and operation, particularly in enterprises requiring reliable and efficient communication solutions.

One of the standout features of the 42C4911 is its modularity. This allows for flexible configurations and upgrades, enabling organizations to adapt to changing technology requirements and business demands. The design philosophy behind the 42C4911 emphasizes scalability, allowing users to start with a basic setup and expand it as their networking needs grow. This feature is particularly appealing to medium and large enterprises that anticipate increased data and communication requirements over time.

In terms of technology, the 42C4911 supports various telecommunications standards, making it versatile for multiple applications. It typically integrates with other Nortel equipment and can work with third-party devices, ensuring seamless interoperability across different platforms. This is critical as organizations look to create unified communications systems that can handle voice, data, and video traffic efficiently.

The 42C4911 is known for its robust performance and reliability. It is designed to operate continuously under demanding conditions, which is essential for organizations that rely on constant connectivity for their operations. Its built-in redundancy features help safeguard against potential failures, thus enhancing the overall stability of the network. This reliability is further complemented by Nortel's commitment to high-quality manufacturing standards, ensuring that users receive a durable and efficient product.

Security is another major consideration for any networking device, and the 42C4911 provides advanced security features to protect sensitive data. With increasing cybersecurity threats, organizations prioritize devices that offer strong encryption and access control mechanisms. The 42C4911 addresses these needs while facilitating secure communication channels for users, which is essential in today's increasingly interconnected world.

Overall, the Nortel Networks 42C4911 stands out as a versatile and powerful component in the telecommunications landscape. Its modular design, compatibility with diverse technologies, reliability, and emphasis on security make it an appealing choice for organizations looking to enhance their networks. As companies continue to navigate the complexities of communication, devices like the 42C4911 play a crucial role in ensuring that they remain connected and efficient.