RFC 8907 Explained: What Changed in the Official TACACS+ Standard

TACACS+ ran for two decades on an expired Internet-Draft with no formal standard behind it. RFC 8907 (IETF, September 2020) documents the protocol as deployed, but as an Informational RFC rather than a Standards Track one, and it describes the protocol’s packet protection as obfuscation, not encryption. RFC 9887 (9 December 2025, Proposed Standard) updates […]

Read more

How Operators Prove AAA Reliability to Regulators and Enterprise Customers

Overview The rest of this cluster asks how you verify a vendor’s reliability claims. This article flips the direction: once your authentication, authorization, and accounting (AAA) platform is reliable, how do you prove it to the regulator who sets the penalties and the enterprise customer who decides whether to renew? Regulators generally want compliance-format reporting: […]

Read more

Multi-Site AAA Server Deployment Best Practices

A multi-site AAA server deployment only survives a site loss if five things are executed, not assumed: subscriber and session state replicated across sites in real time and asynchronously to the auth path; every request routed to the nearest healthy site with NAS (network access server) timers set from measured latency; failover drills that isolate […]

Read more

AAA Server Deployment Timeline: What to Expect

A carrier-grade AAA server deployment timeline runs five phases: planning (2–4 weeks), staging and integration (2–3 weeks), pilot (2–4 weeks), cutover (about a week), and post-go-live stabilization (2–4 weeks), for a typical total of 9–16 weeks. Subscriber scale, protocol scope, integration count, and migration versus greenfield decide where in that range a project lands. Pilot […]

Read more

Credential-Stuffing Attacks on Broadband Networks and How AAA Stops Them

Overview Credential stuffing replays leaked username/password pairs across thousands of subscriber accounts, one or two tries each. Per-account lockout never trips, so the attack looks like background noise until the takeovers start. On a broadband network the login surfaces are RADIUS-backed PPPoE and hotspot authentication, carrier Wi-Fi portals, and self-care accounts. All of them terminate […]

Read more

What to Demand in an AAA Support SLA Beyond 24/7

Summary “24/7 support” only guarantees that a vendor will accept your ticket at any hour. It says nothing about response speed, escalation, expertise, or restoration. Demand response time tiers by severity, with two targets per tier: time to a qualified human (automated acknowledgments do not count) and time to workaround or restoration. You define the […]

Read more

How to Run an AAA Failover Drill Without Dropping Live Subscribers

Every operations team knows failover should be tested, including the AAA (authentication, authorization, and accounting) layer, where the stakes are highest. Knowing how to run an AAA failover drill safely is not the hard part; far fewer teams actually run one, and the reason is rarely laziness. It’s fear. The AAA server sits in the […]

Read more

TACACS+ Security Best Practices for Telecom and Service Provider Networks

These ten TACACS+ security best practices start with attribution (mentioned below): one credential per human, least privilege per command, a second factor on privileged roles. Classic TACACS+ on TCP port 49 obfuscates rather than encrypts, so confine it to a hardened management network and treat shared secrets as cryptographic keys. RFC 9887 (published 9 December […]

Read more

How to Reduce AAA Server Deployment Risk

Reducing AAA (authentication, authorization, and accounting) server deployment risk means addressing six recurring failure modes session-state loss, undersized capacity, protocol misconfiguration, incomplete rollback plans, NAS onboarding gaps, and accounting data mismatches each with a specific, testable mitigation applied before cutover. The risk register table below turns those six into a working project artifact you can […]

Read more

Community Broadband Operators: A Lean Systems Stack That Still Scales

Community and municipal broadband operators face a real tension: budgets say start minimal, growth plans say don’t buy anything you’ll outgrow. The way through is a community broadband lean systems stack, core Authentication, Authorization, and Accounting (AAA) and billing only at launch, chosen on scale-ready architecture rather than feature count. Prioritize subscriber authentication, usage accounting, […]

Read more

Subscribe to our Newsletter

Receive the latest news

Subscribe To Our Newsletter