06-27-2002 02:12 PM - edited 02-21-2020 10:01 AM
we are trying to decide between local id and auth versus tacacs or radius for our administrators. is either one more reliable or secure? what are the pros and cons?
06-27-2002 02:12 PM
An external server is not really more
secure; the data can be encrypted
to the server. Local AAA may be
more reliable, depending on your
network to the external server and the
server itself (another failure point).
If you have multiple router's,
maintenance is likely easier with AAA -
one change and it applies everywhere.
In general, if your network (# of
devices, # of administrators, # of
users, etc) grows handling router
access via an external AAA server is
usually going to be better for the
long run.
06-27-2002 03:29 PM
In my opinion, using tacacs/radius server is more secure, scalable and more control/features than using local AAA. It is good idea to do have local AAA as fallback in the event your radius/tacacs is not available, etc.
HTH
R/Yusuf
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide