A network security engineer is configuring a central remote-access VPN gateway to integrate with an external authentication server. According to the organization's compliance policy, the selected authentication protocol must encrypt the entire packet payload during transit and strictly separate authentication from authorization duties. Which protocol should the engineer implement on the VPN gateway?
- TACACS+Cevap
- BRADIUS
- CLDAP
- DKerberos
Cevap
TACACS+ is the correct choice because it encrypts the full payload of access control packets and decouples authentication, authorization, and accounting functions.
TACACS+ provides full payload encryption (encrypting all data following the standard header) and strictly separates authentication, authorization, and accounting into distinct, independent processes.
Adım Adım Çözüm
Anahtar Kavram
RADIUS vs TACACS+ Protocol Architecture and Security Features