
Fabric OS 5.3.0 administrator guide
81
Vendor-assigned attribute number—Enter the value
1
.
Attribute format—Enter
String
.
Attribute value—Enter the login role (Root, Admin, Factory, SwitchAdmin, or User) the user group must
use to log in to the switch.
17.
In the Multivalued Attribute Information window, click
OK
.
18.
In the Edit Dial-in Profile window, remove all additional parameters (except the one you just added,
“Vendor-Specific”) and click
OK
.
19.
In the Add Remote Access Policy window, click
Finish
.
20.
After returning to the Internet Authentication Service window, repeat steps 5 through 19 to add
additional policies for all login types you want to use the RADIUS server. After this is done, you can
configure the switch.
Configuring RADIUS servers on the switch
RADIUS configuration of the switch is controlled by the
aaaConfig
command.
NOTE:
On dual-CP switches (SAN Director 2/128 and 4/256 SAN Director), the switch sends its
RADIUS request using the IP address of the active CP. When adding clients, add both the active and
standby CP IP addresses so that users can still log in the event of a failover.
The following procedures show how to use the
aaaConfig
command to set up a switch for RADIUS
service.
RADIUS configuration is chassis-based configuration data. On platforms containing multiple switch
instances, the configuration applies to all instances. The configuration is persistent across
reboot
and
firmwareDownload
. On a chassis-based system, the command must replicate the configuration to the
standby CP.
Multiple login sessions can invoke the command simultaneously. The last session that applies the change
be the one whose configuration is in effect. This configuration is persistent after an HA failover.
How to display the current RADIUS configuration
1.
Connect to the switch and log in as
admin
.
2.
Enter this command:
If a configuration exists, its parameters are displayed. If RADIUS service is not configured, only the
parameter heading line is displayed. Parameters include:
switch:admin>
aaaConfig --show
Position
The order in which servers are contacted to provide service
Server
The server names or IP addresses
Port
The server ports
Secret
The shared secrets
Timeouts
The length of time servers have to respond before the next server is
contacted
Authenticati
on
The type of authentication being used on servers
Summary of Contents for AA979A - StorageWorks SAN Switch 2/8V
Page 1: ...HP StorageWorks Fabric OS 5 3 x administrator guide Part number 5697 0244 November 2009 ...
Page 16: ...16 ...
Page 20: ...18 ...
Page 24: ...24 Introducing Fabric OS CLI procedures ...
Page 116: ...118 Maintaining configurations ...
Page 170: ...172 Managing administrative domains ...
Page 200: ...202 Installing and maintaining firmware ...
Page 222: ...224 Routing traffic ...
Page 274: ...286 Administering FICON fabrics ...
Page 294: ...306 Working with diagnostic features ...
Page 350: ...362 Administering Extended Fabrics ...
Page 438: ...440 Configuring the PID format ...
Page 444: ...446 Configuring McData Open Fabric mode ...
Page 450: ...452 Understanding legacy password behaviour ...