RADIUS/TACACS

๐Ÿ” RADIUS & TACACS+ ์„œ๋ฒ„ ๊ตฌ์ถ• ๋ฐ ์„ค์ • ๊ฐ€์ด๋“œ ๐Ÿš€


1๏ธโƒฃ RADIUS & TACACS+๋ž€?

**RADIUS (Remote Authentication Dial-In User Service)**์™€ **TACACS+ (Terminal Access Controller Access-Control System Plus)**๋Š” ๋„คํŠธ์›Œํฌ ์žฅ๋น„ ๋ฐ ์‹œ์Šคํ…œ์— **์‚ฌ์šฉ์ž ์ธ์ฆ, ๊ถŒํ•œ ๋ถ€์—ฌ ๋ฐ ๊ณ„์ • ๊ด€๋ฆฌ(AAA: Authentication, Authorization, Accounting)**๋ฅผ ์ œ๊ณตํ•˜๋Š” ํ”„๋กœํ† ์ฝœ์ž…๋‹ˆ๋‹ค.

โœ… RADIUS์™€ TACACS+์˜ ์ฐจ์ด์ 

ํ”„๋กœํ† ์ฝœ ๋ณด์•ˆ์„ฑ ํฌํŠธ ์•”ํ˜ธํ™” ๋ฐฉ์‹ ์‚ฌ์šฉ์ฒ˜
RADIUS โœ… ์‚ฌ์šฉ์ž ๋น„๋ฐ€๋ฒˆํ˜ธ๋งŒ ์•”ํ˜ธํ™” UDP 1812, 1813 PAP, CHAP, EAP VPN, Wi-Fi ์ธ์ฆ
TACACS+ โœ… ์ „์ฒด ํŒจํ‚ท ์•”ํ˜ธํ™” TCP 49 SSH, Telnet ์ธ์ฆ ๋„คํŠธ์›Œํฌ ์žฅ๋น„ (Cisco ๋“ฑ)

2๏ธโƒฃ RADIUS ์„œ๋ฒ„ ์„ค์น˜ (Linux ๊ธฐ๋ฐ˜)

๐Ÿ”น Ubuntu/Debian์—์„œ FreeRADIUS ์„ค์น˜

sudo apt update
sudo apt install freeradius -y

๐Ÿ”น CentOS/RHEL์—์„œ FreeRADIUS ์„ค์น˜

sudo yum install freeradius freeradius-utils -y

์„ค์น˜ ํ›„, ์„œ๋น„์Šค ํ™œ์„ฑํ™” ๋ฐ ์ƒํƒœ ํ™•์ธ

sudo systemctl enable freeradius
sudo systemctl start freeradius
sudo systemctl status freeradius

3๏ธโƒฃ RADIUS ์„œ๋ฒ„ ์„ค์ •

RADIUS ์ฃผ์š” ์„ค์ • ํŒŒ์ผ์€ /etc/freeradius/3.0/ ๋””๋ ‰ํ† ๋ฆฌ์— ์žˆ์Šต๋‹ˆ๋‹ค.

๐Ÿ“Œ 1. ํด๋ผ์ด์–ธํŠธ(๋„คํŠธ์›Œํฌ ์žฅ๋น„) ์ถ”๊ฐ€

sudo nano /etc/freeradius/3.0/clients.conf

๋‹ค์Œ ๋‚ด์šฉ์„ ์ถ”๊ฐ€ํ•˜์—ฌ RADIUS ํด๋ผ์ด์–ธํŠธ(๋„คํŠธ์›Œํฌ ์žฅ๋น„)๋ฅผ ๋“ฑ๋กํ•ฉ๋‹ˆ๋‹ค.

client router1 {
    ipaddr = 192.168.1.1
    secret = myradiussecret
}

๐Ÿ“Œ 2. ์‚ฌ์šฉ์ž ๊ณ„์ • ์ถ”๊ฐ€

sudo nano /etc/freeradius/3.0/users
testuser Cleartext-Password := "password123"
    Service-Type = Framed-User,
    Framed-Protocol = PPP

์„ค์ •์„ ์ €์žฅํ•œ ํ›„ RADIUS ์„œ๋น„์Šค๋ฅผ ์žฌ์‹œ์ž‘ํ•ฉ๋‹ˆ๋‹ค.

sudo systemctl restart freeradius

4๏ธโƒฃ TACACS+ ์„œ๋ฒ„ ์„ค์น˜

๐Ÿ”น Ubuntu/Debian์—์„œ TACACS+ ์„ค์น˜

sudo apt install tacacs+ -y

๐Ÿ”น CentOS/RHEL์—์„œ TACACS+ ์„ค์น˜

sudo yum install tacacs+ -y

์„ค์น˜ ํ›„, ์„œ๋น„์Šค ํ™œ์„ฑํ™” ๋ฐ ์ƒํƒœ ํ™•์ธ

sudo systemctl enable tacacs+
sudo systemctl start tacacs+
sudo systemctl status tacacs+

5๏ธโƒฃ TACACS+ ์„œ๋ฒ„ ์„ค์ •

TACACS+ ์ฃผ์š” ์„ค์ • ํŒŒ์ผ์€ /etc/tacacs+/tacacs.conf ์ž…๋‹ˆ๋‹ค.

sudo nano /etc/tacacs+/tacacs.conf

๐Ÿ“Œ 1. ๊ณต์œ  ํ‚ค(Shared Secret) ์„ค์ •

key = "tacacs_secret"

๐Ÿ“Œ 2. ์‚ฌ์šฉ์ž ๊ณ„์ • ์ถ”๊ฐ€

user = admin {
    login = cleartext "adminpassword"
    service = exec {
        priv-lvl = 15
    }
}

์„ค์ •์„ ์ €์žฅํ•œ ํ›„ TACACS+ ์„œ๋น„์Šค๋ฅผ ์žฌ์‹œ์ž‘ํ•ฉ๋‹ˆ๋‹ค.

sudo systemctl restart tacacs+

6๏ธโƒฃ ๋ฐฉํ™”๋ฒฝ ์„ค์ • (ํ•„์š”ํ•œ ๊ฒฝ์šฐ)

โœ… RADIUS (UDP 1812, 1813) & TACACS+ (TCP 49) ํฌํŠธ ํ—ˆ์šฉ

๐Ÿ”น UFW (Ubuntu/Debian)

sudo ufw allow 1812/udp
sudo ufw allow 1813/udp
sudo ufw allow 49/tcp
sudo ufw reload

๐Ÿ”น firewalld (CentOS/RHEL)

sudo firewall-cmd --permanent --add-port=1812/udp
sudo firewall-cmd --permanent --add-port=1813/udp
sudo firewall-cmd --permanent --add-port=49/tcp
sudo firewall-cmd --reload

7๏ธโƒฃ RADIUS & TACACS+ ํด๋ผ์ด์–ธํŠธ ์„ค์ •

๐Ÿ“Œ 1. RADIUS ํด๋ผ์ด์–ธํŠธ(๋„คํŠธ์›Œํฌ ์žฅ๋น„) ์„ค์ • ์˜ˆ์‹œ

Cisco ๋ผ์šฐํ„ฐ์—์„œ RADIUS ์ธ์ฆ ํ™œ์„ฑํ™”

configure terminal
radius-server host 192.168.1.100 key myradiussecret
aaa new-model
aaa authentication login default group radius local
aaa authorization exec default group radius local
exit

๐Ÿ“Œ 2. TACACS+ ํด๋ผ์ด์–ธํŠธ(๋„คํŠธ์›Œํฌ ์žฅ๋น„) ์„ค์ • ์˜ˆ์‹œ

Cisco ๋ผ์šฐํ„ฐ์—์„œ TACACS+ ์ธ์ฆ ํ™œ์„ฑํ™”

configure terminal
tacacs-server host 192.168.1.100 key tacacs_secret
aaa new-model
aaa authentication login default group tacacs+ local
aaa authorization exec default group tacacs+ local
exit

8๏ธโƒฃ ๋กœ๊ทธ ํ™•์ธ ๋ฐ ๋ฌธ์ œ ํ•ด๊ฒฐ

๐Ÿ“Œ 1. RADIUS ๋กœ๊ทธ ํ™•์ธ

sudo journalctl -u freeradius -f

๐Ÿ“Œ 2. TACACS+ ๋กœ๊ทธ ํ™•์ธ

sudo tail -f /var/log/tacacs.log

๐Ÿ“Œ 3. ์ธ์ฆ ํ…Œ์ŠคํŠธ (RADIUS)

radtest testuser password123 127.0.0.1 0 myradiussecret

๐Ÿ“Œ 4. ์ธ์ฆ ํ…Œ์ŠคํŠธ (TACACS+)

echo "adminpassword" | tac_pwd

9๏ธโƒฃ ๊ฒฐ๋ก  ๐Ÿš€

โœ… RADIUS์™€ TACACS+๋Š” ๋„คํŠธ์›Œํฌ ๋ฐ ์‹œ์Šคํ…œ ์ธ์ฆ์„ ๊ฐ•ํ™”ํ•˜๋Š” ์ค‘์š”ํ•œ ํ”„๋กœํ† ์ฝœ์ž…๋‹ˆ๋‹ค.
โœ… RADIUS๋Š” VPN, Wi-Fi ์ธ์ฆ์— ์ฃผ๋กœ ์‚ฌ์šฉ, TACACS+๋Š” Cisco ๋„คํŠธ์›Œํฌ ์žฅ๋น„ ์ธ์ฆ์— ์ตœ์ ํ™”๋˜์–ด ์žˆ์Šต๋‹ˆ๋‹ค.
โœ… ๋ณด์•ˆ์ด ์ค‘์š”ํ•œ ํ™˜๊ฒฝ์—์„œ๋Š” TACACS+๋ฅผ, ์ผ๋ฐ˜์ ์ธ ๋„คํŠธ์›Œํฌ ์ธ์ฆ ํ™˜๊ฒฝ์—์„œ๋Š” RADIUS๋ฅผ ์‚ฌ์šฉํ•˜๋Š” ๊ฒƒ์ด ์ข‹์Šต๋‹ˆ๋‹ค.

๐Ÿ“š ์ถ”๊ฐ€ ์ž๋ฃŒ
1๏ธโƒฃ FreeRADIUS ๊ณต์‹ ๋ฌธ์„œ
2๏ธโƒฃ TACACS+ ๊ณต์‹ ๋ฌธ์„œ
3๏ธโƒฃ Cisco RADIUS & TACACS+ ์„ค์ • ๊ฐ€์ด๋“œ


์ด์ œ RADIUS & TACACS+ ์„œ๋ฒ„๋„ ์™„๋ฒฝํ•˜๊ฒŒ ์„ค์ •ํ•  ์ˆ˜ ์žˆ์–ด์š”! ๐Ÿ”ฅ
์ถ”๊ฐ€์ ์œผ๋กœ ์›ํ•˜๋Š” ๊ธฐ๋Šฅ์ด ์žˆ๋‹ค๋ฉด ์–ธ์ œ๋“ ์ง€ ์š”์ฒญํ•ด ์ฃผ์„ธ์š”. ๐Ÿ˜ƒ

RSS Feed
๋งˆ์ง€๋ง‰ ์ˆ˜์ •์ผ์ž