Friday, June 20, 2008

ACE RBAC

Today I started to investigate how to configure ACE (Application Control Engine) module for AAA. The ACE module enforces RBAC (Role Based Access Control) withe roles and domains. RBAC is equates to authorization in the AAA model. The remainder AAA components authentication and accounting can be configured either locally in the ACE module (via command line) or remotely on the AAA server. The ACE module acts as an AAA client and supports the following protocols:
  • TACACS+
  • Radius
  • LDAP
In our next post, we will cover local authentication.

Juniper SA-6000 SSL/VPN:

Hya,

I am currently working on a new hot SSL/VPN technology: Juniper SA-6000.
This gear can support up to 10,000 users when setup in cluster (up to 9 nodes).
Here is an overview:
  • easy management interface through a standard browser
  • supports virtualization (multiple client contexts)
  • acts as a proxy to intranet applications
  • supports overlapping of IP addresses (multi-client environment, outsourcing)
  • OS based on a stripped version of BSD unix