RADIUS-based network authentication, authorization, and accounting (AAA)
The platform acts as a RADIUS server for network access devices, receiving access requests, authenticating the supplied identity, returning an authorization result, and recording accounting records for the session. Authorization results carry the attributes the switch, controller, or gateway applies to the session. Accounting data provides the session start, update, and stop records used for session tracking and reporting.
02
TACACS+ device administration (command authorization and accounting for network devices)
The platform also serves TACACS+ so administrators logging into network devices are authenticated centrally. It authorizes individual commands against defined command sets and shell profiles, so a given administrator group can be limited to specific commands and privilege levels. Every login and command is recorded in accounting logs for audit.
03
802.1X wired, wireless, and VPN authentication enforcement
The platform enforces 802.1X authentication for endpoints connecting on switch ports, wireless networks, and VPN headends. The access device relays EAP exchanges between the endpoint's supplicant and the platform, which validates the identity and returns the authorization result. The same policy set can cover all three access methods, with rules that distinguish them by access type.
04
MAC Authentication Bypass (MAB) for non-802.1X endpoints
For devices that cannot run an 802.1X supplicant, such as printers, cameras, and other embedded equipment, the access device sends the endpoint's MAC address as the identity. The platform checks it against its endpoint database and profiling results and returns an authorization result on that basis. This lets unsupplicant devices be admitted with restricted access appropriate to their identified type.
05
Web authentication (central and local) for fallback access
Users can be authenticated through a web page when other methods do not apply. Centralized web authentication redirects the browser to a portal hosted on the platform after an initial restricted authorization, while local web authentication has the access device host the login. In both cases the credentials are validated by the platform and the session is then reauthorized with the resulting access level.
Your plan caps how many capabilities are shown — upgrade to see the full list