Authentication
After you have identified the daemon and defined an associated encryption key, you
must define method lists for authentication. Because authentication is operated via
AAA, you need to issue the
aaa authentication
command, specifying as the authentication method.
Authorization
AAA authorization enables you to set parameters that restrict a user
’
s access to the network. Authorization
via may be applied to commands, network connections, and EXEC sessions. Because
authorization is facilitated through AAA, you must issue the
aaa authorization
command, specifying
as the authorization method.
Accounting
The AAA accounting feature tracks the services that users are accessing and the amount of network resources
that they are consuming. When AAA accounting is enabled, the switch reports user activity to the
security server in the form of accounting records. Each accounting record contains accounting attribute-value
(AV) pairs and is stored on the security server. This data can then be analyzed for network management, client
billing, or auditing.
Default Configuration
and AAA are disabled by default.
To prevent a lapse in security, you cannot configure through a network management application.
When enabled, can authenticate users accessing the switch through the CLI.
Although configuration is performed through the CLI, the server authenticates
HTTP connections that have been configured with a privilege level of 15.
Note
Per VRF for TACACS Servers
The Per VRF for Servers feature allows per virtual routing and forwarding (VRF) AAA to be
configured on servers. server access is required to configure this feature.
How to Configure
Identifying the Server Host and Setting the Authentication Key
Follow these steps to identify the server host and set the authentication key:
Consolidated Platform Configuration Guide, Cisco IOS Release 15.2(4)E (Catalyst 2960-X Switches)
883
How to Configure
Summary of Contents for Catalyst 2960 Series
Page 96: ......
Page 196: ......
Page 250: ......
Page 292: ......
Page 488: ......
Page 589: ...P A R T VI Cisco Flexible NetFlow Configuring NetFlow Lite page 509 ...
Page 590: ......
Page 619: ...P A R T VII QoS Configuring QoS page 539 Configuring Auto QoS page 645 ...
Page 620: ......
Page 750: ......
Page 1604: ......
Page 1740: ......
Page 2105: ...P A R T XII Configuring Cisco IOS IP SLAs Configuring Cisco IP SLAs page 2025 ...
Page 2106: ......
Page 2118: ......
Page 2164: ......