21-48
Catalyst 6000 Family Software Configuration Guide—Releases 6.3 and 6.4
78-13315-02
Chapter 21 Configuring Switch Access Using AAA
Authentication Example
This example shows how to display the global 802.1x parameters:
Console> (enable)
show dot1x
PAE Capability Authenticator Only
Protocol Version 1
system-auth-control enabled
max-req 2
quiet-period 60 seconds
re-authperiod 3600 seconds
server-timeout 30 seconds
supp-timeout 30 seconds
tx-period 30 seconds
Authentication Example
Figure 21-3
shows a simple network topology using .
In this example, authentication is enabled and local authentication is disabled for both login
and enable access to the switch for all Telnet connections. When Workstation A attempts to connect to
the switch, the user is challenged for a username and password.
However, only local authentication is enabled for both login and enable access on the console port. Any
user with access to the directly connected terminal can access the switch using the login and enable
passwords.
Figure 21-3 Example Network Topology
This example shows how to configure the switch so that authentication is enabled for Telnet
connections, local authentication is enabled for console connections, and a encryption key
is specified:
Console> (enable)
show tacacs
Tacacs key:
Tacacs login attempts: 3
Tacacs timeout: 5 seconds
Tacacs direct request: disabled
Tacacs-Server Status
---------------------------------------- -------
Console> (enable)
set tacacs server 172.20.52.10
172.20.52.10 added to TACACS server table as primary server.
Workstation A
server
172.20.52.10
Switch
Terminal
Console port
connection
18927