9-66
Cisco MGX 8850 (PXM1E/PXM45), Cisco MGX 8950, Cisco MGX 8830, and Cisco MGX 8880 Configuration Guide
Release 5.0.10, OL-3845-01 Rev. B0, August 16, 2004
Chapter 9 Switch Operating Procedures
Managing Remote () Authentication and Authorization
After you enter the cnfaaa-server command, the switch prompts you to enter a encryption key. The
encryption key is a text string that can contain any combination of letters, numbers, spaces, and
characters. This key is required for encrypted communications with the server and must also be entered
at the AAA server. To enter an encryption key, respond to the prompts as shown in the following
example:
M8830_SF.2.PXM.a >
cnfaaa-server
-ip 172.29.52.112
Do you want to change the encryption key (yes/no)?
y
Enter the encryption key:
Re-enter the encryption key:
SERVERS: primary is shown first
Time Dead Single
IP Address Port Out Time Conn Shared Encryption Key
---------------- ---- --- ---- ------ --------------------------------------
172.29.52.111 49 5 0 true
172.29.52.112 49 5 0 true 12345abcde
WARNING: One or more servers do not have a key configured.
Information exchanged with this server will be unencrypted, in clear text.
The encryption key must be entered twice and should be entered without quotation marks, unless the
quotation marks themselves are part of the key. Although white spaces are allowed inside the key, white
spaces are not allowed at the beginning or end of the key; they are automatically stripped off.
Note
For maximum security, Cisco recommends that you use an encryption key for
communications. The encryption key is used to encrypt communications so that user names and
passwords are not easily acquired by unauthorized users. Some AAA servers may require an encryption
key. If the AAA server requires an encryption key, the same key must be configured at the server and at
the Cisco MGX switch.
A configuration without a key is recommended only for troubleshooting or lab testing. When no
encryption key is specified, all communications are in clear text format and are easier to read by
unauthorized users.
If you are not using encryption, just respond to the prompts as shown in the following example:
M8830_SF.2.PXM.a >
cnfaaa-server -ip
172.29.52.111
Do you want to change the encryption key (yes/no)?
n
WARNING: No encrpytion key specified for the protocol. This means
that all information shared with the server will be in cleartext! This is
a security risk.
Do you want to proceed (Yes/No)?
y
SERVERS: primary is shown first
Time Dead Single
IP Address Port Out Time Conn Shared Encryption Key
---------------- ---- --- ---- ------ --------------------------------------
172.29.52.111 49 5 0 true
WARNING: One or more servers do not have a key configured.
Information exchanged with this server will be unencrypted, in clear text.