C
HAPTER
13
| Security Measures
AAA Authorization and Accounting
– 309 –
To configure AAA on the switch, you need to follow this general process:
1.
Configure RADIUS and server access parameters. See
"Configuring Local/Remote Logon Authentication" on page 309
.
2.
Define RADIUS and server groups to support the accounting
and authorization of services.
3.
Define a method name for each service to which you want to apply
accounting or authorization and specify the RADIUS or server
groups to use.
4.
Apply the method names to port or line interfaces.
N
OTE
:
This guide assumes that RADIUS and servers have already
been configured to support AAA. The configuration of RADIUS and
server software is beyond the scope of this guide, refer to the
documentation provided with the RADIUS or server software.
C
ONFIGURING
L
OCAL
/
R
EMOTE
L
OGON
A
UTHENTICATION
Use the Security > AAA > System Authentication page to specify local or
remote authentication. Local authentication restricts management access
based on user names and passwords manually configured on the switch.
Remote authentication uses a remote access authentication server based
on RADIUS or protocols to verify management access.
CLI R
EFERENCES
◆
"Authentication Sequence" on page 813
C
OMMAND
U
SAGE
◆
By default, management access is always checked against the
authentication database stored on the local switch. If a remote
authentication server is used, you must specify the authentication
sequence. Then specify the corresponding parameters for the remote
authentication protocol using the Security > AAA > Server page. Local
and remote logon authentication control management access via the
console port, web browser, or Telnet.
◆
You can specify up to three authentication methods for any user to
indicate the authentication sequence. For example, if you select
(1) RADIUS, (2) TACACS and (3) Local, the user name and password
on the RADIUS server is verified first. If the RADIUS server is not
available, then authentication is attempted using the server,
and finally the local user name and password is checked.
P
ARAMETERS
These parameters are displayed:
◆
Authentication Sequence
– Select the authentication, or
authentication sequence required:
Summary of Contents for ES3528MV2
Page 1: ...Management Guide www edge core com ES3528MV2 ES3528MV2 DC 28 Port Fast Ethernet Layer 2 Switch...
Page 2: ......
Page 4: ......
Page 48: ...CONTENTS 48...
Page 68: ...SECTION I Getting Started 68...
Page 78: ...CHAPTER 1 Introduction System Defaults 78...
Page 96: ...SECTION II Web Configuration 96...
Page 116: ...CHAPTER 3 Using the Web Interface Navigating the Web Browser Interface 116...
Page 148: ...CHAPTER 4 Basic Management Tasks Resetting the System 148...
Page 192: ...CHAPTER 5 Interface Configuration VLAN Trunking 192 Figure 65 Configuring VLAN Trunking...
Page 226: ...CHAPTER 6 VLAN Configuration Configuring VLAN Translation 226...
Page 236: ...CHAPTER 7 Address Table Settings Configuring MAC Address Mirroring 236...
Page 270: ...CHAPTER 9 Congestion Control Automatic Traffic Control 270...
Page 300: ...CHAPTER 11 Quality of Service Attaching a Policy Map to a Port 300...
Page 418: ...CHAPTER 13 Security Measures DHCP Snooping 418...
Page 588: ...CHAPTER 15 IP Configuration Setting the Switch s IP Address IP Version 6 588...
Page 606: ...CHAPTER 16 IP Services Configuring the PPPoE Intermediate Agent 606...
Page 676: ...CHAPTER 17 Multicast Filtering Multicast VLAN Registration for IPv6 676...
Page 772: ...CHAPTER 20 System Management Commands Switch Clustering 772...
Page 802: ...CHAPTER 22 Remote Monitoring Commands 802...
Page 808: ...CHAPTER 23 Flow Sampling Commands 808...
Page 872: ...CHAPTER 24 Authentication Commands PPPoE Intermediate Agent 872...
Page 950: ...CHAPTER 25 General Security Measures Port based Traffic Segmentation 950...
Page 1002: ...CHAPTER 27 Interface Commands Power Savings 1002...
Page 1016: ...CHAPTER 28 Link Aggregation Commands Trunk Status Display Commands 1016...
Page 1046: ...CHAPTER 30 Congestion Control Commands Automatic Traffic Control Commands 1046...
Page 1058: ...CHAPTER 32 UniDirectional Link Detection Commands 1058...
Page 1064: ...CHAPTER 33 Address Table Commands 1064...
Page 1124: ...CHAPTER 35 ERPS Commands 1124...
Page 1168: ...CHAPTER 36 VLAN Commands Configuring Voice VLANs 1168...
Page 1182: ...CHAPTER 37 Class of Service Commands Priority Commands Layer 3 and 4 1182...
Page 1202: ...CHAPTER 38 Quality of Service Commands 1202...
Page 1360: ...CHAPTER 41 CFM Commands Delay Measure Operations 1360...
Page 1382: ...CHAPTER 43 Domain Name Service Commands 1382...
Page 1440: ...SECTION IV Appendices 1440...
Page 1468: ...COMMAND LIST 1468...
Page 1479: ......
Page 1480: ...ES3528MV2 ES3528MV2 DC E112013 ST R03...