5-8
Cisco SCE8000 Software Configuration Guide, Rel 3.1.6S
OL-16479-01
Chapter 5 Configuring the Management Interface and Security
Configuring the Available Interfaces
Privilege level authorization in the SCE platform is accomplished by the use of an "enable" command
authentication request. When a user requests an authorization for a specified privilege level, by using the
"enable" command, the SCE platform sends an authentication request to the server specifying
the requested privilege level. The SCE platform grants the requested privilege level only after the
server does the following:
•
Authenticates the "
enable
" command password
•
Verifies that the user has sufficient privileges to enter the requested privilege level.
Once the user privilege level has been determined, the user is granted access to a specified set of
commands according to the level granted.
As with login authentication, if the server is unavailable, the next authentication method is attempted, as
explained in
General AAA Fallback and Recovery Mechanism, page 5-8
General AAA Fallback and Recovery Mechanism
The SCE platform uses a fall-back mechanism to maintain service availability in case of an error.
The SCE platform uses a fall-back mechanism to maintain service availability in case of an error.
The AAA methods available are:
•
– AAA is performed by the use of a server, allows authentication,
authorization and accounting.
•
Local
– AAA is performed by the use of a local database, allows authentication and authorization.
•
Enable
– AAA is performed by the use of user configured passwords, allows authentication and
authorization.
•
None
– no authentication\authorization\accounting is performed.
In the current implementation the order of the methods used isn't configurable but the customer can
choose which of the methods are used. The current order is
•
•
Local
•
Enable
•
None
Note
If the server goes to AAA fault, the SCE platform will not be accessible until one of the AAA methods
is restored. In order to prevent this, it is advisable to use the "none" method as the last AAA method. If
the SCE platform becomes un-accessible, the shell function "AAA_MethodsReset" will allow the user
to delete the current AAA method settings and set the AAA method used to "Enable".
About Configuring
The following is a summary of the procedure for configuring . All steps are explained in detail
in the remainder of this section.
1.
Configure the remote servers.
Configure the remote servers for the protocols. Keep in mind the following guidelines
–
Configure the encryption key that the server and client will use.
–
The maximal user privilege level and enable password (password used when executing the
enable command) should be provided.