![HP HP ProCurve Series 6600 Access Security Manual Download Page 224](http://html.mh-extra.com/html/hp/hp-procurve-series-6600/hp-procurve-series-6600_access-security-manual_163101224.webp)
5-20
Authentication
Configuring on the Switch
Figure 5-6. Example of Configuring a Host-Specific Key
Use the
show running-config
command to display the key information.
• If there are two or more vacant slots in the server priority list and you enter a new IP address, the new
address will take the vacant slot with the highest priority. Thus, if A, B, and C are configured as above and you (1)
remove A and B, and (2) enter X and Y (in that order), then the new server priority list would be X, Y, and C.
• The easiest way to change the order of the servers in the priority list is to remove all server addresses in
the list and then re-enter them in order, with the new first-choice server address first, and so on.
To add a new address to the list when there are already three addresses present, you must first remove one of the currently
listed addresses.
See also “General Authentication Process Using a Server” on page 5-24.
key <
key-string
>
none (null) n/a
Specifies the optional, global “encryption key” that is also assigned in the server(s) that the switch will access
for authentication. This option is subordinate to any “per-server” encryption keys you assign, and applies only to
accessing servers for which you have not given the switch a “per-server” key. (See the
host <
ip-addr
> [key
<
key-string
>
entry at the beginning of this table.)
You can configure a encryption key that includes a tilde (~) as part of the key, for example, “hp~switch”. It is
not backward compatible; the “~” character is lost if you use a software version that does not support the “~” character
For more on the encryption key, see “Using the Encryption Key” on page 5-26 and the documentation provided with your
server application.
timeout <1 - 255>
5 sec
1 - 255 sec
Specifies how long the switch waits for a server to respond to an authentication request. If the switch does
not detect a response within the timeout period, it initiates a new request to the next server in the list. If all
servers in the list fail to respond within the timeout period, the switch uses either local authentication (if
configured) or denies access (if
none
configured for local authentication).
Name
Default
Range
HP Switch(config)# tacacs-server host 10.10.10.2 key hp~switch
Summary of Contents for HP ProCurve Series 6600
Page 2: ......
Page 6: ...iv ...
Page 26: ...xxiv ...
Page 102: ...2 48 Configuring Username and Password Security Password Recovery ...
Page 204: ...4 72 Web and MAC Authentication Client Status ...
Page 550: ...10 130 IPv4 Access Control Lists ACLs General ACL Operating Notes ...
Page 612: ...12 24 Traffic Security Filters and Monitors Configuring Traffic Security Filters ...
Page 734: ...14 44 Configuring and Monitoring Port Security Operating Notes for Port Security ...
Page 756: ...16 8 Key Management System Configuring Key Chain Management ...
Page 776: ...20 Index web server proxy 14 42 webagent access 6 6 wildcard See ACL wildcard See ACL ...
Page 777: ......