Link to home
Start Free TrialLog in
Avatar of jazzIIIlove
jazzIIIloveFlag for Sweden

asked on

what is RADIUS and TACACS+ in your own words.

Hi;

What is RADIUS and TACACS+ in your own words? What are they used for? And Where? No wikipedia please.

Br.
Avatar of Michael Best
Michael Best
Flag of Japan image

For an excellent explanation please refer to the techexams.net post by Darril Gibson
Link:
 http://www.techexams.net/forums/security/48766-what-difference-between-tacacs-radius.html
Avatar of Kanti Prasad
Kanti Prasad

Sorry Wolfe -- I was just trying to help and I did not know that there will be such objection.

 jazzIIIlove : Here is some info which I am writing with my own understanding and I hope you will find it useful.

 TACACS+ and RADIUS (RFC 2865 - Spec) are Security Protocols of Cisco to control access into networks.

RADIUS is an access server that uses AAA protocol. It secures remote access to networks and network services against unauthorized access. RADIUS has a client, a server and a protocol with a frame format that utilizes User Datagram Protocol (UDP)/IP. RADIUS uses UDP which is best effort transport.RADIUS encrypts only the password in the access-request packet, from the client to the server. The remainder of the packet is unencrypted, RADIUS does not multiprotocol protocols ((ARA,NetBIOS , NASI & •X.25 PAD ). RADIUS Request for Comments (RFCs) does not guarantee interoperability.RADIUS does not allow users control on routers. RADIUS combines authentication and authorization hence in router management it cannot decouple authentication, exec authorization, command authorization, exec accounting, and command accounting.

TACACS+ protocol has independent authentication, authorization, and accounting (AAA) architecture that is designed to support growing security markets, It uses TCP which is connection oriented transport.TACACS+ encrypts the entire body of the packet but leaves a standard TACACS+ header. TACACS+ offers multiprotocol support(ARA,NetBIOS , NASI & •X.25 PAD ). TACACS+ allows control on routers.TACACS+ decouples  authentication and authorization hence  in router management it can decouple authentication, exec authorization, command authorization, exec accounting, and command accounting.
Avatar of jazzIIIlove

ASKER

Hi;

Thanks any fundamental difference between them?

Also are those protocols used by ISPs? Where is their place in OSI layer?

Best regards.
ASKER CERTIFIED SOLUTION
Avatar of Kanti Prasad
Kanti Prasad

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial