Posts

Showing posts with the label Network Management

Out-of-Band Management: A Separate Path for When the Network Is Down

In-band management reaches a device over the same network the device carries traffic on. It works until the thing you need to fix is the network itself — a bad configuration change, a failed routing update, a switch that will not come back after a reboot. Out-of-band management provides a separate path that does not depend on the production network being healthy. What it looks like A console server aggregates serial console ports from network equipment and presents them over the management network, so an administrator can reach the same prompt they would get standing at the device with a laptop and a console cable. Serial access works at a level nothing else does: it survives a device with no IP configuration, it shows boot messages, and it can interrupt the boot process for password recovery. A baseboard management controller — sold as iDRAC, iLO, IPMI, or XCC depending on vendor — is a small independent computer on the server's motherboard with its own processo...

TACACS+ vs RADIUS: Command Authorization and Device Administration

TACACS+ and RADIUS both provide authentication, authorization and accounting, and they are used for different jobs. The short version: TACACS+ for administering network devices, RADIUS for authenticating users and endpoints onto the network. Most well-run networks run both, and knowing why is the exam point. The architectural difference RADIUS combines authentication and authorization into a single exchange. When a user authenticates successfully, the accept response carries the authorization attributes with it — one transaction, one decision. TACACS+ separates all three functions into independent exchanges. Authentication establishes identity. Authorization is then queried separately, and — crucially — can be queried repeatedly during the same session. Accounting is a third independent stream. That separation is what enables per-command authorization, which is the capability RADIUS structurally cannot provide. Per-command authorization With TACACS+, every com...