![Cisco 2948G - Catalyst Switch Configuration Manual Download Page 453](http://html.mh-extra.com/html/cisco/2948g-catalyst-switch/2948g-catalyst-switch_configuration-manual_67462453.webp)
30-9
Catalyst 4500 Series, Catalyst 2948G, Catalyst 2980G Switches Software Configuration Guide
—
Release 8.1
78-15486-01
Chapter 30 Configuring Switch Access Using AAA
Configuring Authentication
Authentication Configuration Guidelines
This section lists the guidelines for configuring authentication on the switch:
•
Authentication configuration applies both to console and Telnet connection attempts unless you use
the console and telnet keywords to specify the authentication methods to use for each connection
type individually.
•
If you configure a RADIUS or key on the switch, make sure that you configure an
identical key on the RADIUS or server.
•
The key must be less than 100 characters long.
•
You must specify a RADIUS or server before enabling RADIUS or on the
switch.
•
If you configure multiple RADIUS or servers, the first server that you configure is the
primary server, and authentication requests are sent to this server first. You can specify a particular
server as primary by using the primary keyword.
•
RADIUS and support one privileged mode only (level 1).
•
Kerberos authentication does not work if is also used as an authentication mechanism.
•
Before you can enable local user authentication, you must define at least one username.
•
Local user accounts and passwords must be fewer than 65 characters and can consist of any
alphanumeric characters. Local user accounts must contain at least one alphabetic character.
Configuring Login Authentication
The next two sections describe how to configure login authentication on the switch.
Kerberos login authentication (console and Telnet)
Disabled
Kerberos enable authentication (console and Telnet)
Disabled
Kerberos server IP address
None specified
Kerberos DES key
None specified
Kerberos server auth-port
Port 750
Kerberos local-realm name
NULL string
Kerberos credentials forwarding
Disabled
Kerberos clients mandatory
Not mandatory
Kerberos preauthentication
Disabled
Table 30-2 Default Authentication Configuration (continued)
Feature
Default