
30-31
Catalyst 4500 Series, Catalyst 2948G, Catalyst 2948G-GE-TX, and Catalyst 2980G Switches Software Configuration Guide—Release 8.2GLX
78-15908-01
Chapter 30 Configuring Switch Access Using AAA
Configuring Authentication
Step 2
Add the switch to the database. The following example adds a switch called Cat4012 to the CISCO.EDU
database:
ank host/[email protected]
Step 3
Add the username as follows:
Step 4
Add the Administrative Principals as follows:
ank user1/[email protected]
Step 5
Create the entry for the switch in the database using the admin.local ktadd command as follows:
ktadd host/[email protected]
Step 6
Move the keyadmin file to a place where the switch can reach it.
Step 7
Start the KDC server as follows:
/usr/local/sbin/krb4kdc
/usr/local/sbin/kadmind
Enabling Kerberos
To enable Kerberos authentication, perform this task in privileged mode:
This example shows how to enable Kerberos as the login authentication method for Telnet and verify the
configuration:
Console> (enable) set authentication login kerberos enable telnet
kerberos login authentication set to enable for telnet session.
Console> (enable) show authentication
Login Authentication: Console Session Telnet Session
--------------------- ---------------- ----------------
tacacs disabled disabled
radius disabled disabled
kerberos disabled enabled(primary)
local enabled(primary) enabled
Enable Authentication:Console Session Telnet Session
---------------------- ----------------- ----------------
tacacs disabled disabled
radius disabled disabled
kerberos disabled enabled(primary)
local enabled(primary) enabled
Console> (enable)
Task
Command
Step 1
Enable Kerberos authentication.
set authentication login kerberos enable [all |
console | http | telnet] [primary]
Step 2
Verify the configuration.
show authentication