Core: Security
AAA and identity - RADIUS, TACACS+, 802.1X
Requirement / business driver Authenticate and authorise both who administers the devices and what/who connects to the network, with an audit trail. TACACS+ vs RADIUS TACACS+RADIUS Primary useDevice administration (CLI)Network access (802.1X/MAB, VPN) TransportTCP 49UDP 1812/1813 EncryptionEntire payloadPassword only GranularityPer-command authorizationAuthorize at access (coarse)