
SecureStack C2 Configuration Guide
18-1
18
Security Configuration
This
chapter
describes
the
Security
Configuration
set
of
commands
and
how
to
use
them.
Overview of Security Methods
The
following
security
methods
are
available
for
controlling
which
users
are
allowed
to
access,
monitor,
and
manage
the
switch.
•
Login
user
accounts
and
passwords
–
used
to
log
in
to
the
CLI
via
a
Telnet
connection
or
local
COM
port
connection.
For
details,
refer
to
•
Host
Access
Control
Authentication
(HACA)
–
authenticates
user
access
of
Telnet
management,
console
local
management
and
WebView
via
a
central
RADIUS
Client/Server
application.
When
RADIUS
is
enabled,
this
essentially
overrides
login
user
accounts.
When
HACA
is
active
per
a
valid
RADIUS
configuration,
the
user
names
and
passwords
used
to
access
the
switch
via
Telnet,
SSH,
WebView,
and
COM
ports
will
be
validated
against
the
configured
RADIUS
server.
Only
in
the
case
of
a
RADIUS
timeout
will
those
credentials
be
compared
against
credentials
locally
configured
on
the
switch.
For
details,
refer
to
•
SNMP
user
or
community
names
–
allows
access
to
the
SecureStack
C2
switch
via
a
network
SNMP
management
application.
To
access
the
switch,
you
must
enter
an
SNMP
user
or
community
name
string.
The
level
of
management
access
is
dependent
on
the
associated
access
policy.
For
details,
refer
to
•
802.1X
Port
Based
Network
Access
Control
using
EAPOL
(Extensible
Authentication
Protocol)
–
provides
a
mechanism
via
a
RADIUS
server
for
administrators
to
securely
For information about...
Refer to page...
Configuring 802.1X Authentication
Configuring MAC Authentication
Configuring Multiple Authentication Methods
Configuring VLAN Authorization (RFC 3580)
Configuring Port Web Authentication (PWA)
Summary of Contents for SecureStack C2
Page 1: ...SecureStack C2 Stackable Switches Configuration Guide Firmware Version 5 1 xx P N 9033991 16 ...
Page 2: ......
Page 28: ...xxvi ...
Page 106: ...set ssl 3 52 Basic Configuration ...
Page 226: ...Creating a Basic SNMP Trap Configuration 6 38 SNMP Configuration ...
Page 278: ...show spantree nonforwardingreason 7 52 Spanning Tree Configuration ...
Page 302: ...set garp timer 8 24 802 1Q VLAN Configuration ...
Page 448: ...show dhcp pool configuration 14 30 DHCP Server Configuration ...
Page 454: ...no license advanced 15 6 Preparing for Router Mode ...