
Configuring Authentication
Cisco AS5300 Universal Access Server Software Configuration Guide
4-4
Configuring Authentication
You can use the AAA facility to authenticate users with either a local or a remote security database.
Whether you maintain a local or remote security database, or use or RADIUS
authentication and authorization, the process of configuring the access server for these different
databases and protocols is similar. The basic process of configuring the Cisco IOS software for
authentication requires the following tasks:
1
Securing Access to Privileged EXEC and Configuration Mode
2
Communicating Between the Access Server and the Security Server
3
Configuring Authentication on a Server
4
Enabling AAA Globally on the Access Server
5
Defining Authentication Method Lists
— Enter the aaa authentication Command
— Specify Protocol or Login Authentication
— Identify a List Name
— Specify the Authentication Method
— Populate the Local Username Database if Necessary
6
Applying Authentication Method Lists
Securing Access to Privileged EXEC and Configuration Mode
The first step to configuring authentication is to secure access to privileged EXEC (also called
enable) mode. Enable mode provides access to configuration mode, which enables any type of
configuration change to the access server. To secure Privileged EXEC mode, use one of the
commands listed in Table 4-1.
Pri
For more information about the enable password and enable secret commands and their complete
syntax, refer to the Security Command Reference, available online at
http://www.cisco.com/univercd/cc/td/doc/product/software/ios113ed/113ed_cr/secur_c/
Table 4-1
Privileged EXEC Mode Commands
Command
Description
enable password password
Requires that network administrators enter a password to access enable mode.
Do not provide access to users who are not administrators.
enable secret password
Specifies a secret password that is encrypted, so that the password cannot be
read when crossing a network. After you enter this command, the encryption
cannot be reversed. The encrypted version of the password appears in output
of the show running-config and show startup-config commands. The enable
secret password has precedence over the enable password. Do not enter the
same password as the enable password. If the two passwords are the same, the
enable secret password is not a secret, because the enable password is not
encrypted and appears in output of show running-config and show
startup-config commands.
Summary of Contents for AS5300 - Universal Access Server
Page 4: ......
Page 10: ...x Book Title ...
Page 34: ...Where to Go Next Cisco AS5300 Universal Access Server Software Configuration Guide 2 6 ...
Page 160: ...Cisco AS5300 Universal Access Server Software Configuration Guide ROM Monitor Commands B 8 ...
Page 184: ...Cisco AS5300 Universal Access Server Software Configuration Guide Where to Go Next C 24 ...
Page 192: ...Cisco AS5300 Universal Access Server Software Configuration Guide New Hardware Features D 8 ...