HP网络安全教学课件03AAA02AAA技术的基本概念原理及协议.ppt
2013 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without noticen 认证和授权是安全网络中不可缺少的一环认证和授权是安全网络中不可缺少的一环n 认证和授权是抵御不安全因素进入网络的重要防线认证和授权是抵御不安全因素进入网络的重要防线引入引入2013 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without noticen 了解了解AAA体系结构体系结构n 了解认证授权在实际中的应用了解认证授权在实际中的应用课程目标课程目标学习完本课程,您应该能够:学习完本课程,您应该能够:2013 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without noticen AAA体系结构体系结构n 认证授权应用认证授权应用目录目录2013 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice网络设备数量不断增加2. 安全管理处于分散管理控制水平3. 不利于工行“下管一级、监控两级”网络管理原则 网络建设项目概述2013 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice网络维护工作中经常发生的为每个值班人员分配username和password需要值班人员经常查看设备的运行状态(接口、路由、CPU)简单的控制命令:shutdown, no shutdown值班人员的supervisor设备控制能力错误的操作,带来设备reload无意中删除关键配置,网络中断2013 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice设备控制管理方法定义username和password/每个设备定义privilege0-15 command set将username与privilege关联缺点:在所有设备上实施同样的配置没有操作记录能力管理和控制复杂username one privilege 15 password one username four privilege 7 password four privilege exec level 7 pingprivilege exec level 7 clear line Privilege 0Privilege 123.14Privilege 15用户定义RouterRouterenableRouter#2013 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice使用AAA实现安全管理 Authentication 控制谁可以访问设备?Authorization 控制他/她在设备上可以做什么?Accounting 监视记录其操作过程?2013 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice利用ACS实现AAA管理 Cisco Secure ACSTelnet AdminTACACS+RADIUSConsole AdminCisco Secure ACSTelnet AdminTACACS+RADIUSConsole AdminRSA服务器服务器动态口令验证动态口令验证动态口令技术提高密码的安全性动态口令技术提高密码的安全性ACSACS基本认证功能的实现基本认证功能的实现2013 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without noticeAAA安全架构AAA:认证、授权、计费依托RADIUS等协议完成认证、授权和计费提供多域满足ISP应用提供服务器的备份方案应用于接入认证,管理授权等多领域被访问网络 用户名密码 验证结果RADIUS服务器TACACS+服务器其他备份服务器HostAHostBNAS 用户名密码 验证结果2013 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without noticen AAA体系结构体系结构n 认证授权应用认证授权应用目录目录2013 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice用户接入认证授权用户有着多种接入认证授权方式本地认证授权RADIUS认证授权CA认证授权用户直接发起连接总部用户直接发起连接用户RADIUS认证RADIUS2013 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice登录设备认证授权登录设备有着多种接入认证授权方式本地认证授权RADIUS认证授权用户登录设备本地认证2013 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice设备间协议认证设备间的协议认证大多采用本地认证本地认证本地认证BGP邻居模式设备接口AAA相关命令字符模式tty,vty,aux,conLogin,exec,nasi connection,enable,command数据包模式Async,group-async,BRI,PRI,serial,diaer profiles,dialer rotaries ppp,network设备间的协议认证采用AAA认证的举例2013 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without noticen 讲述了讲述了AAA体系架构体系架构n 讲述了认证授权功能在实际组网中的应用讲述了认证授权功能在实际组网中的应用本章总结本章总结2013 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without noticeTHANK YOU 海南人才20000 HP Education Mar. 2013