RADIUS

Remote Authentication Dial In User Service: a client-server AAA protocol (RFC 2865) that carries authentication, authorisation and accounting between network access devices and a central server.

RADIUS (Remote Authentication Dial In User Service) is a protocol for centralised authentication, authorisation and accounting, defined in RFC 2865, with accounting in RFC 2866. A network access server, such as a VPN gateway or switch, acts as the client and passes the user’s credentials to a central server, which returns an accept, a reject, or a challenge asking for more information. Authorisation travels inside the authentication response. RADIUS runs over UDP. Transactions between client and server are authenticated with a shared secret that is never sent over the network, and the user’s password is hidden with an MD5-based method (RFC 2865 sections 1 and 5.2), while most other attributes are sent in the clear.

It is commonly contrasted with TACACS+, which runs over TCP and separates authentication, authorisation and accounting into distinct exchanges, suiting device administration and per-command authorisation. Study sources commonly say TACACS+ encrypts the whole body, but RFC 8907 calls that protection obfuscation, so both need a protected network or transport. Diameter is commonly described as the successor to RADIUS. RADIUS is also the usual authentication server behind IEEE 802.1X and enterprise Wi-Fi.

Exam relevance: a scenario is likely to describe network or remote access users authenticated centrally, or to contrast RADIUS with TACACS+. Candidates are expected to associate RADIUS with UDP, combined authentication and authorisation, and protection of the password only.