6-12
RADIUS Authentication, Authorization, and Accounting
Configuring the Switch for RADIUS Authentication
Figure 6-3. Example Configuration for RADIUS Authentication
N o t e
If you configure the Login Primary method as
local
instead of
radius
(and local
passwords are configured on the switch), then clients connected to your
network can gain access to either the Operator or Manager level without
encountering the RADIUS authentication specified for Enable Primary. Refer
to “Local Authentication Process” on page 6-34.
2. Enable the (Optional) Access Privilege Option
In the default RADIUS operation, the switch automatically admits any authen-
ticated client to the Login (Operator) privilege level, even if the RADIUS server
specifies Enable (Manager) access for that client. Thus, an authenticated user
authorized for the Manager privilege level must authenticate again to change
privilege levels. Using the optional
login privilege-mode
command overrides
HP Switch(config)# aaa authentication telnet login radius none
HP Switch(config)# aaa authentication telnet enable radius none
HP Switch(config)# aaa authentication ssh login radius none
HP Switch(config)# aaa authentication ssh enable radius none
HP Switch(config)# show authentication
Status and Counters - Authentication Information
Login Attempts : 3
Respect Privilege : Disabled
| Login Login Login
Access Task | Primary Server Group Secondary
----------- + ---------- ------------ ----------
Console | Local None
Telnet | Radius None
Port-Access | Local None
Webui | Local None
SSH | Radius None
Web-Auth | ChapRadius radius None
MAC-Auth | ChapRadius radius None
| Enable Enable Enable
Access Task | Primary Server Group Secondary
----------- + ---------- ------------ ----------
Console | Local None
Telnet | Radius None
Webui | Local None
SSH | Radius None
The switch now
allows Telnet and
SSH authentication
only through
RADIUS.
Summary of Contents for E3800 Series
Page 2: ......
Page 3: ...HP Networking E3800 Switches Access Security Guide September 2011 KA 15 03 ...
Page 30: ...xxviii ...
Page 86: ...2 36 Configuring Username and Password Security Password Recovery ...
Page 186: ...4 72 Web and MAC Authentication Client Status ...
Page 364: ...8 32 Configuring Secure Shell SSH Messages Related to SSH Operation ...
Page 510: ...10 130 IPv4 Access Control Lists ACLs General ACL Operating Notes ...
Page 548: ...11 38 Configuring Advanced Threat Protection Using the Instrumentation Monitor ...
Page 572: ...12 24 Traffic Security Filters and Monitors Configuring Traffic Security Filters ...
Page 730: ...20 Index ...
Page 731: ......