Configuring the switch
148
offers the following advantages over RADIUS as the authentication device:
•
is TCP-based, so it facilitates connection-oriented traffic.
•
It supports full-packet encryption, as opposed to password-only in authentication requests.
•
It supports decoupled authentication, authorization, and accounting.
The following table describes Switch Configuration controls:
Table 100
Switch Configuration controls
Control Description
Primary IP Address
Configures the primary server address.
Secondary IP Address
Configures the secondary server address.
port (1-65000)
Configures the number of the TCP port to be configured,
between 1 and 65000. The default is 49.
timeout (4-15)
Configures the amount of time, in seconds, before a
server authentication attempt is considered to have failed. The
default timeout is 5 seconds.
retries (1-3)
Configures the number of failed authentication requests before
switching to a different server. The default retry count is
3 requests.
Enable/Disable Server
Enables or disables the server.
Enable/Disable Backdoor for
telnet/ssh/http/https
Enables or disables the backdoor for
telnet/SSH/HTTP/HTTPS.
Enable/Disable Secure Backdoor for
telnet
Enables or disables the back door using secure
password for telnet/SSH/HTTP/HTTPS.
Enable/Disable new privilege level
mapping
Enables or disables privilege-level mapping.
The default value is disabled.
Secret
Configures the shared secret (up to 32 characters) between the
switch and the server.
Secondary Server Secret
Configures the secondary shared secret (up to 32 characters)
between the switch and the server.
User Mappings Configuration
Maps a privilege level to a HP 1:10GbE switch user
level, as follows:
Remote Privilege—Enter a privilege level (0-15)
Local Privilege—Select the corresponding switch user level.