A network security architect must implement centralized AAA management for network administrators executing commands on enterprise routers across loss-prone WAN links. The solution must support per-command authorization policy enforcement, encrypt the entire packet payload during transit, and use a reliable connection-oriented transport protocol to guarantee delivery of accounting records. Which protocol and transport combination should the architect deploy?
- TACACS+ utilizing TCP port 49Cevap
- BRADIUS utilizing UDP ports 1812 and 1813
- CTACACS+ utilizing UDP ports 1812 and 1813
- DRADIUS utilizing TCP port 49
Cevap
TACACS+ utilizing TCP port 49
TACACS+ (Terminal Access Controller Access-Control System Plus) fully decouples the AAA functions, enabling separate per-command authorization checks for router administration. It encrypts the complete packet payload (except the standard header) and uses connection-oriented TCP on port 49, satisfying the WAN reliability and accounting delivery requirements.
Adım Adım Çözüm
Anahtar Kavram
Decoupled AAA architecture, payload encryption scope, and transport protocol characteristics of TACACS+ versus RADIUS.