Configuring Security
Key Management
Cisco 500 Series Stackable Managed Switch Administration Guide
306
18
Key Management
See
Chapter 23, “Key Management”
. Covered in the RIP Chapter.
Configuring Management Access Authentication
You can assign authentication methods to the various management access
methods, such as SSH, console, Telnet, HTTP, and HTTPS. The authentication can
be performed locally or on a or RADIUS server.
For the RADIUS server to grant access to the web-based switch configuration
utility, the RADIUS server must return cisco-avpair = shell:priv-lvl=15.
User authentication occurs in the order that the authentication methods are
selected. If the first authentication method is not available, the next selected
method is used. For example, if the selected authentication methods are RADIUS
and Local, and all configured RADIUS servers are queried in priority order and do
not reply, the user is authenticated locally.
If an authentication method fails or the user has insufficient privilege level, the user
is denied access to the switch. In other words, if authentication fails at an
authentication method, the switch stops the authentication attempt; it does not
continue and does not attempt to use the next authentication method.
To define authentication methods for an access method:
STEP 1
Click
Security
>
Management Access Authentication
. The
Management Access
Authentication
page is displayed.
STEP 2
Select an access method from the
Application
list.
STEP 3
Use the arrows to move the authentication method between the Optional Methods
column and the Selected Methods column. The first method selected is the first
method that is used.
•
RADIUS
—User is authenticated on a RADIUS server. You must have
configured one or more RADIUS servers.
•
—User authenticated on the server. You must have
configured one or more servers.