37 aaa, Overview, Introduction to aaa – H3C Technologies H3C WX6000 Series Access Controllers User Manual

Page 423

Advertising
background image

37-1

37

AAA

The sample output in this manual was created on the WX5004. The output on your device may

vary.

The grayed out functions or parameters on the Web interface indicate that they are not supported

or cannot be modified.

The models listed in this manual are not applicable to all regions. Please consult your local sales

office for the models applicable to your region.

Overview

Introduction to AAA

Authentication, Authorization, and Accounting (AAA) provides a uniform framework for configuring

these three security functions to implement network security management.

AAA usually uses a client/server model, where the client runs on the network access server (NAS) and

the server maintains user information centrally. In an AAA network, a NAS is a server for users but a

client for the AAA servers, as shown in

Figure 37-1

.

Figure 37-1 AAA networking diagram

When a user tries to establish a connection to the NAS and to obtain the rights to access other networks

or some network resources, the NAS authenticates the user or the corresponding connection. The NAS

takes the responsibility to transparently pass the user’s AAA information to the server (RADIUS server,

for example). The RADIUS protocol defines how a NAS and a server exchange user information

between them.

Advertising