data:image/s3,"s3://crabby-images/7bf28/7bf28718679d69319184eff6a4510af4dc3b914e" alt="Cisco 4006 - Catalyst Switch Configuration Manual Download Page 479"
30-33
Catalyst 4500 Series, Catalyst 2948G, Catalyst 2948G-GE-TX, and Catalyst 2980G Switches Software Configuration Guide—Release 8.2GLX
78-15908-01
Chapter 30 Configuring Switch Access Using AAA
Configuring Authentication
Specifying a Kerberos Server
You can specify to the switch which KDC to use in a specific Kerberos realm. Optionally, you can also
specify the port number of the port that the KDC is monitoring. The Kerberos server maintains
information that you enter in a table with one entry for each Kerberos realm. The maximum number of
entries in the table is 100.
To specify the Kerberos server, perform this task in privileged mode:
This example shows how to define which Kerberos server will serve as the KDC for the specified
Kerberos realm and how to clear the entry:
Console> (enable) set kerberos server CISCO.COM 187.0.2.1 750
Kerberos Realm-Server-Port entry set to:CISCO.COM - 187.0.2.1 - 750
Console> (enable)
Console> (enable) clear kerberos server CISCO.COM 187.0.2.1 750
Kerberos Realm-Server-Port entry CISCO.COM-187.0.2.1-750 deleted
Console> (enable)
Mapping a Kerberos Realm to a Host Name or DNS Domain
Optionally, you can map a host name or Domain Name Server (DNS) domain to a Kerberos realm.
To map a Kerberos realm to either a host name or DNS domain, perform this task in privileged mode:
This example shows how to map a Kerberos realm, called CISCO.COM, to a DNS domain and how to
clear the entry:
Console> (enable) set kerberos realm CISCO CISCO.COM
Kerberos DnsDomain-Realm entry set to CISCO - CISCO.COM
Console> (enable)
Console> (enable) clear kerberos realm CISCO CISCO.COM
Kerberos DnsDomain-Realm entry CISCO - CISCO.COM deleted
Console> (enable)
Task
Command
Step 1
Specify which KDC to use in a given Kerberos
realm. Optionally, enter the port number that the
KDC is monitoring. (The default port number is
750.)
set kerberos server kerberos-realm {hostname |
ip-address} [port-number]
Step 2
Clear the Kerberos server entry.
clear kerberos server kerberos-realm {hostname
| ip-address} [port-number]
Task
Command
Step 1
(Optional) Map a host name or DNS domain to a
Kerberos realm.
set kerberos realm {dns-domain | host}
kerberos-realm
Step 2
Clear the Kerberos realm domain or host mapping entry. clear kerberos realm {dns-domain | host}
kerberos-realm