A network administrator is configuring centralized administration for network switches. The organization's security policy mandates that every CLI command executed by administrators must be individually authorized and audited, and all traffic between the switch and authentication server must be completely encrypted. Which authentication protocol should the administrator deploy to satisfy these requirements?
- TACACS+Cevap
- BRADIUS
- C802.1X
- DKerberos
Cevap
TACACS+ is the correct choice because it encrypts the full packet payload and supports granular per-command authorization and accounting for network device administration.
TACACS+ (Terminal Access Controller Access-Control System Plus) separates authentication, authorization, and accounting functions. It encrypts the complete body of the packet for enhanced privacy and allows administrators to enforce per-command authorization rules on network devices.
Adım Adım Çözüm
Anahtar Kavram
TACACS+ vs RADIUS for Network Device Administration
Tahmini Süre:1m 15s