![Alcatel OmniSwitch 6600-P24 Management Manual Download Page 179](http://html1.mh-extra.com/html/alcatel/omniswitch-6600-p24/omniswitch-6600-p24_management-manual_2891387179.webp)
Managing Switch Security
Authenticated Switch Access
OmniSwitch 6600 Family Switch Management Guide
April 2006
page 8-5
Authentication-only—ACE/Server
Authentication-only servers are able to authenticate users for switch management access, but authoriza-
tion (or what privileges the user has after authenticating) are determined by the switch. Authentication-
only servers cannot return user privileges or end-user profiles to the switch. The authentication-only server
supported by the switch is ACE/Server, which is a part of RSA Security’s SecurID product suite. RSA
Security’s ACE/Agent is embedded in the switch.
The following illustration shows the two different user types attempting to authenticate with an ACE/
Server:
Note.
A RADIUS server supporting the challenge and response mechanism as defined in RADIUS
RFC 2865 may access an ACE/Server for authentication purposes. The ACE/Server is then used for user
authentication, and the RADIUS server is used for user authorization.
Interaction With the User Database
By default, switch management users may be authenticated through the console port via the local user
database. If external servers are configured for other management interfaces (such as Telnet, or HTTP) but
the servers become unavailable, the switch will poll the local user database for login information.
Access to the console port provides secure failover in case of misconfiguration or if external authentica-
tion servers become unavailable. The
admin
user is always authorized through the console port via the
local database (provided the correct password is supplied), even if access to the console port is disabled.
The database includes information about whether or not a user is able to log into the switch and which
kinds of privileges or rights the user has for managing the switch. The database may be set up by the
admin
user or any user with write privileges to the AAA commands.
See
Chapter 7, “Managing Switch User Accounts,”
for more information about setting up the user data-
base.
OmniSwitch 6648
OmniSwitch 6648
The switch polls the server
for login information; end-
user profiles are stored on
the switch.
ACE/Server
OmniSwitch
login request
The switch polls the server
for login information; privi-
leges are stored on the
switch.
ACE/Server
Authentication-Only Server (ACE/Server)
Customer
login request
OmniSwitch
Network Administrator
OmniSwitch 6648
OmniSwitch 6648
user
privilege
s
end-user
profiles