58
Managing user accounts
Configuring the authentication model
This section explains how to configure authentication of the switch management channel connections.
Fabric OS 5.2.x and higher supports use of both the local user database and RADIUS service at the same
time. Use the
aaaConfig
command to set the authentication model for Fabric OS switch management
channel connection authentication model as shown in
Table 12
.
NOTE:
Set the authentication model on each switch.
How to set the switch authentication model
1.
Connect to the switch and log in.
2.
Enter this command:
Managing the local database user accounts
User add, change, and delete operations are subject to the
subset
rule: an admin with ADlist 0-10 cannot
perform operations on an
admin
,
user
, or
any
role with an ADlist 11-25. The user account being changed
must have an ADlist that is a subset of the account that is making the change.
Table 12
Authentication configuration options
aaaConfig Option Description
Equivalent setting in
Fabric OS 5.1.x and later
--radius
--switchdb
1
1.
Fabric OS 5.1.x and earlier aaaConfig --switchdb <on | off> setting.
--localonly
Default setting. Authenticates management
connections against the local database only.
If the password does not match or the user is not
defined, the login fails.
Off
On
--radiusonly
2
2.
The console login will never be set to
--radiusonly
mode for login recovery purposes. When
-
-radiusonly
mode is turned on, console login uses the
--radiuslocalbackup
mode.
Authenticates management connections against
the RADIUS database(s) only.
If the RADIUS service is not available or the
credentials do not match, the log in fails.
On
Off
--radiuslocal
Authenticates management connections against
any RADIUS databases first.
If RADIUS fails
for any reason
, authenticates
against the local user database.
not supported not supported
--radiuslocalbackup
Authenticates management connections against
any RADIUS databases.
If RADIUS fails because the service is not
available, authenticates against the local user
database.
On
On
switch:admin>
aaaConfig [--localonly | --radiusonly | --radiuslocal |
--radiuslocalbackup]
Summary of Contents for AE370A - Brocade 4Gb SAN Switch 4/12
Page 18: ...18 ...
Page 82: ...82 Managing user accounts ...
Page 102: ...102 Configuring standard security features ...
Page 126: ...126 Maintaining configurations ...
Page 198: ...198 Routing traffic ...
Page 238: ...238 Using the FC FC routing service ...
Page 260: ...260 Administering FICON fabrics ...
Page 280: ...280 Working with diagnostic features ...
Page 332: ...332 Administering Extended Fabrics ...
Page 414: ...398 Configuring the PID format ...
Page 420: ...404 Configuring interoperability mode ...
Page 426: ...410 Understanding legacy password behaviour ...
Page 442: ...426 ...
Page 444: ......
Page 447: ......