AI Anomaly Detection for Authentication Traffic: What to Look For in a Platform
How to separate real AI detection capability from marketing language when evaluating AAA vendors.
How to separate real AI detection capability from marketing language when evaluating AAA vendors.
Learn how to troubleshoot common 802.1X authentication failures, including supplicant, certificate, RADIUS, MTU, VLAN, and network issues.
TACACS+ ran for two decades on an expired Internet-Draft with no formal standard behind it. RFC 8907 (IETF, September 2020) documents the protocol as deployed, but as an Informational RFC rather than a Standards Track one, and it describes the protocol’s packet protection as obfuscation, not encryption. RFC 9887 (9 December 2025, Proposed Standard) updates […]
Overview The rest of this cluster asks how you verify a vendor’s reliability claims. This article flips the direction: once your authentication, authorization, and accounting (AAA) platform is reliable, how do you prove it to the regulator who sets the penalties and the enterprise customer who decides whether to renew? Regulators generally want compliance-format reporting: […]
A multi-site AAA server deployment only survives a site loss if five things are executed, not assumed: subscriber and session state replicated across sites in real time and asynchronously to the auth path; every request routed to the nearest healthy site with NAS (network access server) timers set from measured latency; failover drills that isolate […]
A carrier-grade AAA server deployment timeline runs five phases: planning (2–4 weeks), staging and integration (2–3 weeks), pilot (2–4 weeks), cutover (about a week), and post-go-live stabilization (2–4 weeks), for a typical total of 9–16 weeks. Subscriber scale, protocol scope, integration count, and migration versus greenfield decide where in that range a project lands. Pilot […]
Overview Credential stuffing replays leaked username/password pairs across thousands of subscriber accounts, one or two tries each. Per-account lockout never trips, so the attack looks like background noise until the takeovers start. On a broadband network the login surfaces are RADIUS-backed PPPoE and hotspot authentication, carrier Wi-Fi portals, and self-care accounts. All of them terminate […]
Summary “24/7 support” only guarantees that a vendor will accept your ticket at any hour. It says nothing about response speed, escalation, expertise, or restoration. Demand response time tiers by severity, with two targets per tier: time to a qualified human (automated acknowledgments do not count) and time to workaround or restoration. You define the […]
Every operations team knows failover should be tested, including the AAA (authentication, authorization, and accounting) layer, where the stakes are highest. Knowing how to run an AAA failover drill safely is not the hard part; far fewer teams actually run one, and the reason is rarely laziness. It’s fear. The AAA server sits in the […]
These ten TACACS+ security best practices start with attribution (mentioned below): one credential per human, least privilege per command, a second factor on privileged roles. Classic TACACS+ on TCP port 49 obfuscates rather than encrypts, so confine it to a hardened management network and treat shared secrets as cryptographic keys. RFC 9887 (published 9 December […]