@bo chen 你说的对,如上的表格中有关于radius和Tacacs的差异比较,其中提到了题干中的描述。
@lucaslee05 802.1x认证和AD一般不会存在冲突的概念,比较典型的案例是“基于802.1X与Windows AD域联动认证”,他们可以配合起来使用,当然,如果不需要AD的身份数据库,也可以用认证服务器本地的一些账户来进行相关认证。
好的 大概理解了 非常谢谢啊
关于802.1X,如果我们在用户端采用802.1X的协议,那么会跟Active Directory相闯 & 有冲突吗?
你好,
如果这个题是对于客户端做802.1x认证的,感觉应该选A吧?
如果说这个是针对AP的管理的AAA认证授权,那么选择B我觉得能够理解。
RADIUS | TACACS+ |
RADIUS stands for Remote Authentication Dial-In User Service. | TACACS+ is an abbreviation of Terminal Access Controller Access-Control System Plus. |
Documented in RFC 2865. | Described in RFC 1492. |
RADIUS uses User Datagram Protocol (UDP) as Transport Layer Protocol. | TACACS+ uses Transmission Control Protocol (TCP) as Transport Layer Protocol. |
RADIUS uses UDP port 1812 or 1645 for authentication and port 1813 or 1646 for accounting. | TACACS uses TCP port 49 to communicate between the client and server. |
RADIUS provides no support for the external authorization of commands. | TACACS+ provides control over the authorization of commands, allowing granular control. |
RADIUS encrypts passwords only, leaving other information unencrypted. | TACACS+ encrypts all packets. |
RADIUS bundles authentication and authorization, making it impossible to perform them separately. Accounting can be used separately. | TACACS+ separates Authentication, Authorization, and Accounting, making it possible to use different protocols for authentication and authorization or accounting. |
RADIUS does not support command accounting. | TACACS+ supports command accounting. |
RADIUS is an open-standard protocol that works with virtually all modern devices. | TACACS+ is Cisco’s proprietary protocol and works with Cisco devices only. |
RADIUS supports only one privilege level (limited to privilege mode) | TACACS+ supports multiple privilege levels. |
RADIUS supports 802.1x. port-based network access control | TACACS+ does not support 802.1x port-based network access control. |
RADIUS is mainly a network access protocol. | TACACS+ is mainly used for device administration using Access Control Server (ACS) servers. |
RADIUS has no multiprotocol support – IP only. | TACACS+ has multiprotocol support (IP, Novell, NetBIOS, Apple, X.25). |
RADIUS cannot authenticate network devices. | TACACS+ can authenticate network devices. |
@bo chen 你说的对,如上的表格中有关于radius和Tacacs的差异比较,其中提到了题干中的描述。
@lucaslee05 802.1x认证和AD一般不会存在冲突的概念,比较典型的案例是“基于802.1X与Windows AD域联动认证”,他们可以配合起来使用,当然,如果不需要AD的身份数据库,也可以用认证服务器本地的一些账户来进行相关认证。