CCNA focus: Keep the three A's separate. A successful login proves identity, but authorisation still decides allowed actions and accounting records what happened.
02 // Building blocks
Know what each part does.
01
Authentication
Proves or validates who a user or device is.
02
Authorisation
Determines what an authenticated identity is allowed to do.
03
Accounting
Records actions, sessions and resource use for audit and operations.
04
Central AAA
Applies consistent identity policy while local credentials can provide a carefully controlled fallback.
03 // Compare and recognise
Read the clues.
Item
What to remember
TACACS+
TCP 49; commonly used for granular network-device administration.
RADIUS
UDP 1812 authentication/authorisation and 1813 accounting are common; widely used for network access.
Method list
An ordered set of AAA methods and fallbacks.
Least privilege
Authorise only the commands and resources required for the role.
04 // Login decision
Login decision.
1. Administrator opens SSH session2. Device authenticates identity with central AAA server3. Server authorises permitted role or commands4. Device records start, actions and stop events5. If policy permits and server is unreachable, controlled local fallback is tried
Read the example from top to bottom, then verify the resulting state. Configuration is only complete when the output matches the intended design.
05 // Exam and troubleshooting
Turn facts into a method.
TCP 49; commonly used for granular network-device administration.
UDP 1812 authentication/authorisation and 1813 accounting are common; widely used for network access.
An ordered set of AAA methods and fallbacks.
Authorise only the commands and resources required for the role.
Exam checkpoint: Keep the three A's separate. A successful login proves identity, but authorisation still decides allowed actions and accounting records what happened.