Why Use AAA?
Well, recall that any discussion of AAA explains that AAA stands for Authentication, Authorization, and Accounting. So if you need to Authenticate users, Authorize what they are allowed to do (by user or user group), or do Accounting, AAA is the tool of choice. In this article we’ll focus on authenticating router administrators. Much the same approach can be used to authenticate VPN users. ACS can be used as a local database of users. However, I’ve called ACS a “glue” product before — the point being it glues router or VPN or other authentication to your directory server of choice. Cisco network devices generally know how to talk TACACS+ or RADIUS to ACS, and then ACS talks to your Active Directory, LDAP, or other authentication database. As mentioned in my last ACS article, the profiles now provide for different behavior based on user group and device type. Thus ACS opens the door to very flexible authentication of users for various networking purposes. It also provides a login trail