09.12.2012 Views

Understanding the network.pdf - Back to Home

Understanding the network.pdf - Back to Home

Understanding the network.pdf - Back to Home

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

hostnames (which can be corrected with major changes <strong>to</strong> <strong>the</strong> code).<br />

KerberosV5 added full hostname support, <strong>the</strong> ability <strong>to</strong> choose <strong>the</strong><br />

encryption method by adding encryption algorithm identifier tags <strong>to</strong><br />

messages, and au<strong>the</strong>ntication forwarding (which allows a server <strong>to</strong><br />

act on behalf of a client for certain application functions). The Cisco<br />

IOS only has support for version 5.<br />

IOS's Kerberos support provides kerberized application access (Telnet,<br />

rlogin, and so on) from <strong>the</strong> USER exec and access-server<br />

au<strong>the</strong>ntication. Accounting must still be provided with RADIUS or<br />

TACACS.<br />

The following are online resources for RADIUS, TACACS and<br />

Kerberos:<br />

RADIUS:<br />

http://www.merit.edu/aaa/basicsvr.html<br />

ftp://ftp.merit.edu/radius/releases/radius.3.6B.basic.tar<br />

http://www.merit.edu/radius/releases/radius.3.6B.basic.tar<br />

TACACS:<br />

http://fxnet.missouri.org/individuals/wes/tacplus.html<br />

ftp://ftp-eng.cisco.com/pub/xtacacs/<br />

http://www.easynet.de/tacacs-faq/<br />

CiscoSecure 2.0 (TACACS+)<br />

http://www.cisco.com/warp/public/480/tacplus.shtml<br />

http://www.cisco.com/warp/public/480/cssample2x.html<br />

CiscoSecure 1.0 (TACACS+)<br />

http://www.cisco.com/warp/public/480/cssample.html<br />

Kerberos:<br />

http://gost.isi.edu/info/kerberos/<br />

http://web.mit.edu/kerberos/www/

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!