Foundation Summary

To configure security on a Cisco router or access server using AAA, follow these steps:

Step 1. Activate AAA services by using the aaa new-model command.

Step 2. Select the type of security protocols, such as RADIUS, TACACS+, or Kerberos.

Step 3. Define the method list's authentication by using an aaa authentication command.

Step 4. Apply the method lists to a particular interface or line, if required.

Step 5. (Optional) Configure authorization using the aaa authorization command.

Step 6. (Optional) Configure accounting using the aaa accounting command.

• show aaa server Displays RADIUS servers used for AAA authentication

• show aaa user Displays AAA authenticated users statistics

• debug aaa authentication Displays debugging messages on authentication functions

• debug aaa authorization Displays debugging messages on authorization functions

• debug aaa accounting Displays debugging messages on accounting functions



1. Which command enables AAA on a router/NAS?

2. Which of the AAA services can be used for billing and auditing?

3. What is the difference between console and network AAA authorization supported on the Cisco IOS Software?

4. Which AAA command would you use to configure authentication for login to an access server?

5. Where is authorization information stored for each user?

6. Which command enables you to troubleshoot a AAA accounting problem?

7. What types of auditing methods can be specified in a AAA configuration?

8. What is the difference between a FAIL response and an ERROR response in a AAA configuration?

9. How do you display all the detailed accounting records for actively accounted functions? 10. What command disables AAA functionality on your access server?


Chapter 8. Configuring RADIUS and TACACS+ on Cisco IOS Software

