188
C
HAPTER
23: AAA&RADIUS C
ONFIGURATION
Network diagram
Figure 58
Remote RADIUS authentication of Telnet users
Configuration procedure
1
Enter system view.
<S4200G>
system-view
System View: return to User View with Ctrl+Z.
[4200G]
2
Adopt AAA authentication for Telnet users
[4200G]
user-interface vty 0 4
[4200G-ui-vty0-4]
authentication-mode scheme
3
Configure an ISP domain.
[4200G]
domain cams
[4200G-isp-cams]
access-limit enable 10
[4200G-isp-cams]
quit
4
Configure a RADIUS scheme.
[4200G]
radius scheme cams
[4200G-radius-cams]
accounting optional
[4200G-radius-cams]
primary authentication 10.110.91.164 1812
[4200G-radius-cams]
key authentication expert
[4200G-radius-cams]
server-type 3Com
[4200G-radius-cams]
user-name-format with-domain
[4200G-radius-cams]
quit
5
Associate the ISP domain with the RADIUS scheme.
[4200G]
domain cams
[4200G-isp-cams]
scheme radius-scheme cams
A Telnet user logging into the switch by a name in the format of
userid
@cams
belongs to the cams domain and will be authenticated according to the configuration
of the cams domain.
Local Authentication
of FTP/Telnet Users
The configuration procedure for the local authentication of FTP users is similar to that
of Telnet users. The following description only takes the local authentication of Telnet
users as example.
Authentication Server
IP address: 10.110.91.164
Internet
Sw itch
Telnet user
Internet
Authentication Server
IP address: 10.110.91.164
Internet
Sw itch
Authentication server
IP address: 10.110.91.164
Internet
Sw itch
Telnet user
Internet
Authentication Server
IP address: 10.110.91.164
Internet
Sw itch
Authentication Server
IP address: 10.110.91.164
Internet
Sw itch
Telnet user
Internet
Authentication Server
IP address: 10.110.91.164
Internet
Sw itch
Authentication server
IP address: 10.110.91.164
Internet
Sw itch
Telnet user
Internet
Summary of Contents for 4200G 12-Port
Page 10: ...8 CONTENTS...
Page 14: ...4 ABOUT THIS GUIDE...
Page 46: ...32 CHAPTER 5 LOGGING IN THROUGH WEB BASED NETWORK MANAGEMENT SYSTEM...
Page 48: ...34 CHAPTER 6 LOGGING IN THROUGH NMS...
Page 60: ...46 CHAPTER 9 VLAN CONFIGURATION...
Page 64: ...50 CHAPTER 10 MANAGEMENT VLAN CONFIGURATION...
Page 80: ...66 CHAPTER 13 GVRP CONFIGURATION...
Page 98: ...84 CHAPTER 15 LINK AGGREGATION CONFIGURATION...
Page 112: ...98 CHAPTER 18 MAC ADDRESS TABLE MANAGEMENT...
Page 126: ...112 CHAPTER 19 LOGGING IN THROUGH TELNET...
Page 162: ...148 CHAPTER 20 MSTP CONFIGURATION...
Page 274: ...260 CHAPTER 29 IGMP SNOOPING CONFIGURATION...
Page 276: ...262 CHAPTER 30 ROUTING PORT JOIN TO MULTICAST GROUP CONFIGURATION...
Page 298: ...284 CHAPTER 33 SNMP CONFIGURATION...
Page 304: ...290 CHAPTER 34 RMON CONFIGURATION...
Page 338: ...324 CHAPTER 36 SSH TERMINAL SERVICES...
Page 356: ...342 CHAPTER 38 FTP AND TFTP CONFIGURATION...
Page 365: ...Information Center Configuration Example 351 S4200G terminal logging...
Page 366: ...352 CHAPTER 39 INFORMATION CENTER...
Page 378: ...364 CHAPTER 40 BOOTROM AND HOST SOFTWARE LOADING...
Page 384: ...370 CHAPTER 41 Basic System Configuration and Debugging...
Page 388: ...374 CHAPTER 43 NETWORK CONNECTIVITY TEST...
Page 406: ...392 CHAPTER 45 CONFIGURATION OF NEWLY ADDED CLUSTER FUNCTIONS...