取消
显示结果 
搜索替代 
您的意思是: 
cancel
1553
查看次数
0
有帮助
5
回复

Wireless!802.1x个跟AAA区别

lucaslee05
Spotlight
Spotlight

早安大家,

其实802.1x个跟AAA最大区别是什么啊,有点困惑!

这个答案为啥是B?感觉B跟C都是答案啊

1111.jpg

2 个已接受解答

已接受的解答

bo chen
Spotlight
Spotlight

题干针对于无线接入点(APs),哪一个协议必须被实施为支持授权和认证分离解决方案。

所以我认为答案是B,因为802.1X是针对于终端用户(iphone windows mac)做认证准入的,而 APs是网络设备。RADIUS的话认证和授权是combined的,不满足题干要求的separate,所以正确答案是B,TACACS+。

在原帖中查看解决方案

@bo chen 你说的对,如上的表格中有关于radius和Tacacs的差异比较,其中提到了题干中的描述。

@lucaslee05 802.1x认证和AD一般不会存在冲突的概念,比较典型的案例是“基于802.1X与Windows AD域联动认证”,他们可以配合起来使用,当然,如果不需要AD的身份数据库,也可以用认证服务器本地的一些账户来进行相关认证。

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Rps-Cheers | If it solves your problem, please mark as answer. Thanks !

在原帖中查看解决方案

5 条回复5

bo chen
Spotlight
Spotlight

题干针对于无线接入点(APs),哪一个协议必须被实施为支持授权和认证分离解决方案。

所以我认为答案是B,因为802.1X是针对于终端用户(iphone windows mac)做认证准入的,而 APs是网络设备。RADIUS的话认证和授权是combined的,不满足题干要求的separate,所以正确答案是B,TACACS+。

好的 大概理解了 非常谢谢啊

关于802.1X,如果我们在用户端采用802.1X的协议,那么会跟Active Directory相闯 & 有冲突吗? 

你好,

如果这个题是对于客户端做802.1x认证的,感觉应该选A吧?

如果说这个是针对AP的管理的AAA认证授权,那么选择B我觉得能够理解。

TACACS+ vs. RADIUS: Differences Table

RADIUS TACACS+
RADIUS stands for Remote Authentication Dial-In User Service. TACACS+ is an abbreviation of Terminal Access Controller Access-Control System Plus.
Documented in RFC 2865. Described in RFC 1492.
RADIUS uses User Datagram Protocol (UDP) as Transport Layer Protocol. TACACS+ uses Transmission Control Protocol (TCP) as Transport Layer Protocol.
RADIUS uses UDP port 1812 or 1645 for authentication and port 1813 or 1646 for accounting. TACACS uses TCP port 49 to communicate between the client and server.
RADIUS provides no support for the external authorization of commands. TACACS+ provides control over the authorization of commands, allowing granular control.
RADIUS encrypts passwords only, leaving other information unencrypted. TACACS+ encrypts all packets.
RADIUS bundles authentication and authorization, making it impossible to perform them separately. Accounting can be used separately. TACACS+ separates Authentication, Authorization, and Accounting, making it possible to use different protocols for authentication and authorization or accounting.
RADIUS does not support command accounting. TACACS+ supports command accounting.
RADIUS is an open-standard protocol that works with virtually all modern devices. TACACS+ is Cisco’s proprietary protocol and works with Cisco devices only.
RADIUS supports only one privilege level (limited to privilege mode) TACACS+ supports multiple privilege levels.
RADIUS supports 802.1x. port-based network access control TACACS+ does not support 802.1x port-based network access control.
RADIUS is mainly a network access protocol. TACACS+ is mainly used for device administration using Access Control Server (ACS) servers.
RADIUS has no multiprotocol support – IP only. TACACS+ has multiprotocol support (IP, Novell, NetBIOS, Apple, X.25).
RADIUS cannot authenticate network devices. TACACS+ can authenticate network devices.
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Rps-Cheers | If it solves your problem, please mark as answer. Thanks !

题干是separate authentication and authorization,就是为了让你排除radius的。RADIUS bundles authentication and authorization,TACACS+ separates Authentication, Authorization,所以答案只能是B,TACACS+。

@bo chen 你说的对,如上的表格中有关于radius和Tacacs的差异比较,其中提到了题干中的描述。

@lucaslee05 802.1x认证和AD一般不会存在冲突的概念,比较典型的案例是“基于802.1X与Windows AD域联动认证”,他们可以配合起来使用,当然,如果不需要AD的身份数据库,也可以用认证服务器本地的一些账户来进行相关认证。

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Rps-Cheers | If it solves your problem, please mark as answer. Thanks !
快捷链接