168
Using the CLI
• The user password is saved internally in encrypted format and never
appears in clear text anywhere on the CLI.
• The CLI supports and Radius authentication servers.
• The CLI allows the user to configure primary and secondary
authentication servers. If the primary authentication server fails to respond
within a configurable period, the CLI automatically tries the secondary
authentication server.
• The user can specify whether the CLI should revert to using local user
accounts when the remote authentication servers do not respond or if the
CLI simply fails the login attempt because the authentication servers are
down. This requirement applies only when the user is login through a
telnet or an SSH session.
• The CLI always allows the user to log in to a local serial port even if the
remote authentication server(s) are down. In this case, CLI reverts to using
the locally configured accounts to allow the user to log in.
User Access Control
In addition to authenticating a user, the CLI also assigns the user access to
one of two security levels. Level 1 has read-only access. This level allow the
user to read information but not configure the switch. The access to this level
cannot be modified. Level 15 is the special access level assigned to the
superuser of the switch. This level has full access to all functions within the
switch and can not be modified.
If the user account is created and maintained locally, each user is given an
access level at the time of account creation. If the user is authenticated
through remote authentication servers, the authentication server is
configured to pass the user access level to the CLI when the user is
authenticated. When Radius is used, the
Vendor-Specific Option
field
returns the access level for the user. Two vendor specific options are
supported. These are CISCO-AV-Pairs(Shell:priv-lvl=x) and Dell Radius VSA
(user-group=x). provides the appropriate level of access.
The following rules and specifications apply:
• The user determines whether remote authentication servers or locally
defined user authentication accounts are used.
Summary of Contents for PowerConnect 6224
Page 54: ...54 Contents show ip https 1369 state 1370 ...
Page 134: ...134 Command Groups ...
Page 186: ...186 Using the CLI ...
Page 216: ...216 ACL Commands ...
Page 236: ...236 Address Table Commands ...
Page 250: ...250 CDP Interoperability Commands ...
Page 256: ...256 DHCP Layer 2 Relay Commands Example console config dhcp l2relay vlan 10 340 345 ...
Page 284: ...284 Dynamic ARP Inspection Commands ...
Page 318: ...318 Ethernet Configuration Commands ...
Page 330: ...330 GVRP Commands ...
Page 344: ...344 IGMP Snooping Commands ...
Page 368: ...368 IP Addressing Commands ...
Page 378: ...378 IPv6 Access List Commands ...
Page 386: ...386 IPv6 MLD Snooping Querier Commands MLD Version Indicates the version of MLD ...
Page 393: ...LACP Commands 393 Oper Key 29 Partner System Priority 0 MAC Address 000000 000000 Oper Key 14 ...
Page 394: ...394 LACP Commands ...
Page 404: ...404 Link Dependency Commands ...
Page 432: ...432 LLDP Commands ...
Page 446: ...446 Port Monitor Commands 1 Enable 1 g10 1 g8 Rx Tx ...
Page 572: ...572 TACACS Commands ...
Page 610: ...610 VLAN Commands ...
Page 616: ...616 Voice VLAN Commands ...
Page 618: ...618 802 1x Commands 802 1x Option 81 radius server attribute 4 ...
Page 656: ...656 ARP Commands IP Address MAC Address Interface Type Age console ...
Page 822: ...822 IPv6 Routing Commands ...
Page 826: ...826 Loopback Interface Commands ...
Page 828: ...828 Multicast Commands show ip pimsm rphash show ip pimsm rp mapping ...
Page 854: ...854 Multicast Commands ...
Page 930: ...930 OSPF Commands ...
Page 933: ...OSPFv3 Commands 933 show ipv6 ospf virtual link show ipv6 ospf virtual link brief ...
Page 1004: ...1004 PIM SM Commands ...
Page 1014: ...1014 Router Discovery Protocol Commands ...
Page 1054: ...1054 Autoconfig Commands boot host dhcp boot host retry count show boot ...
Page 1058: ...1058 Autoconfig Commands ...
Page 1094: ...1094 Captive Portal Commands ...
Page 1110: ...1110 Clock Commands ...
Page 1130: ...1130 Configuration and Image File Commands ...
Page 1142: ...1142 Denial of Service Commands ...
Page 1178: ...1178 Power Over Ethernet Commands ...
Page 1220: ...1220 Serviceability Tracing Packet Commands ...
Page 1232: ...1232 Sflow Commands ...
Page 1262: ...1262 SNMP Commands ...
Page 1346: ...1346 System Management Commands 4 5 ...
Page 1350: ...1350 Telnet Server Commands ...
Page 1372: ...1372 Web Server Commands ...