12
Workshop CCNA Security Authentication, Authorization and Accounting Preview

Workshop CCNA Security - Typepad · 2019. 11. 9. · Security Using 802.1X Port-Based Authentication 802.1X Message Exchange 802.1X Roles. 802.1X Port Authorization State Command

  • Upload
    others

  • View
    24

  • Download
    0

Embed Size (px)

Citation preview

Page 1: Workshop CCNA Security - Typepad · 2019. 11. 9. · Security Using 802.1X Port-Based Authentication 802.1X Message Exchange 802.1X Roles. 802.1X Port Authorization State Command

WorkshopCCNA Security

Authentication, Authorization and Accounting

Preview

Page 2: Workshop CCNA Security - Typepad · 2019. 11. 9. · Security Using 802.1X Port-Based Authentication 802.1X Message Exchange 802.1X Roles. 802.1X Port Authorization State Command

Authentication without AAATelnet is Vulnerable to Brute-Force Attacks

Page 3: Workshop CCNA Security - Typepad · 2019. 11. 9. · Security Using 802.1X Port-Based Authentication 802.1X Message Exchange 802.1X Roles. 802.1X Port Authorization State Command

Authentication without AAA (Cont.)SSH and Local Database Method

Page 4: Workshop CCNA Security - Typepad · 2019. 11. 9. · Security Using 802.1X Port-Based Authentication 802.1X Message Exchange 802.1X Roles. 802.1X Port Authorization State Command

AAA Components

Page 5: Workshop CCNA Security - Typepad · 2019. 11. 9. · Security Using 802.1X Port-Based Authentication 802.1X Message Exchange 802.1X Roles. 802.1X Port Authorization State Command

Authentication Modes

Local AAA

Authentication

Server-Based

AAA Authentication

Page 6: Workshop CCNA Security - Typepad · 2019. 11. 9. · Security Using 802.1X Port-Based Authentication 802.1X Message Exchange 802.1X Roles. 802.1X Port Authorization State Command

Authorization

AAA Authorization

Page 7: Workshop CCNA Security - Typepad · 2019. 11. 9. · Security Using 802.1X Port-Based Authentication 802.1X Message Exchange 802.1X Roles. 802.1X Port Authorization State Command

Accounting

Types of accounting information:

Network

Connection

EXEC

System

Command

Resource

AAA Accounting

Page 8: Workshop CCNA Security - Typepad · 2019. 11. 9. · Security Using 802.1X Port-Based Authentication 802.1X Message Exchange 802.1X Roles. 802.1X Port Authorization State Command

RADIUS Authentication

RADIUS Authentication Process

Page 9: Workshop CCNA Security - Typepad · 2019. 11. 9. · Security Using 802.1X Port-Based Authentication 802.1X Message Exchange 802.1X Roles. 802.1X Port Authorization State Command

Integration of AAA with Active Directory

Page 10: Workshop CCNA Security - Typepad · 2019. 11. 9. · Security Using 802.1X Port-Based Authentication 802.1X Message Exchange 802.1X Roles. 802.1X Port Authorization State Command

Security Using 802.1X Port-Based Authentication

802.1X Message Exchange

802.1X Roles

Page 11: Workshop CCNA Security - Typepad · 2019. 11. 9. · Security Using 802.1X Port-Based Authentication 802.1X Message Exchange 802.1X Roles. 802.1X Port Authorization State Command

802.1X Port Authorization State

Command Syntax for dot1x port-control

Page 12: Workshop CCNA Security - Typepad · 2019. 11. 9. · Security Using 802.1X Port-Based Authentication 802.1X Message Exchange 802.1X Roles. 802.1X Port Authorization State Command

Workshop preview

1. Authentication and authorization on a Cisco device through Radius on a NPS

server

2. 802.1x authentication – PEAP-MS-CHAPv2

3. Extra : 802.1x authentication – PEAP with TLS