Security Fundamentals // Lesson 08

AAA.

Compare authentication, authorisation and accounting, and recognise how TACACS+ and RADIUS centralise control.

AuthenticationAuthorisationAccountingTACACS+RADIUS
01 // Mental model

Start with the big picture.

Proves or validates who a user or device is.

CCNA focus: Keep the three A's separate. A successful login proves identity, but authorisation still decides allowed actions and accounting records what happened.
02 // Building blocks

Know what each part does.

01

Authentication

Proves or validates who a user or device is.

02

Authorisation

Determines what an authenticated identity is allowed to do.

03

Accounting

Records actions, sessions and resource use for audit and operations.

04

Central AAA

Applies consistent identity policy while local credentials can provide a carefully controlled fallback.

03 // Compare and recognise

Read the clues.

ItemWhat to remember
TACACS+TCP 49; commonly used for granular network-device administration.
RADIUSUDP 1812 authentication/authorisation and 1813 accounting are common; widely used for network access.
Method listAn ordered set of AAA methods and fallbacks.
Least privilegeAuthorise only the commands and resources required for the role.
04 // Login decision

Login decision.

1. Administrator opens SSH session
2. Device authenticates identity with central AAA server
3. Server authorises permitted role or commands
4. Device records start, actions and stop events
5. If policy permits and server is unreachable, controlled local fallback is tried

Read the example from top to bottom, then verify the resulting state. Configuration is only complete when the output matches the intended design.

05 // Exam and troubleshooting

Turn facts into a method.

  • TCP 49; commonly used for granular network-device administration.
  • UDP 1812 authentication/authorisation and 1813 accounting are common; widely used for network access.
  • An ordered set of AAA methods and fallbacks.
  • Authorise only the commands and resources required for the role.
Exam checkpoint: Keep the three A's separate. A successful login proves identity, but authorisation still decides allowed actions and accounting records what happened.
06 // Check yourself

AAA quiz.

1. Which AAA function verifies identity?

2. Which AAA function decides permitted commands?

3. Which protocol commonly uses TCP port 49?

4. What does accounting provide?

5. Why define a fallback method?

Score: 0 / 5