
6-10
RADIUS Authentication, Authorization, and Accounting
Configuring the Switch for RADIUS Authentication
1. Configure Authentication for the Access Methods
You Want RADIUS To Protect
This section describes how to configure the switch for RADIUS authentication
through the following access methods:
■
Console:
Either direct serial-port connection or modem connection.
■
Telnet:
Inbound Telnet must be enabled (the default).
■
SSH:
To use RADIUS for SSH access, first configure the switch for
SSH operation. Refer to chapter 8, “Configuring Secure Shell (SSH)” .
■
WebAgent:
You can enable RADIUS authentication for WebAgent
access to the switch.
You can configure RADIUS as the primary password authentication method
for the above access methods. You also need to select either
local
,
none,
or
authorized
as a secondary, or backup, method. Note that for console access, if
you configure
radius
(or
tacacs
) for primary authentication, you must config-
ure
local
for the secondary method. This prevents the possibility of being
completely locked out of the switch in the event that all primary access
methods fail.
Syntax:
aaa authentication < console | telnet | ssh | web | < enable | login <local
| radius>> web-based | mac-based <chap-radius | peap-radius>>
Configures RADIUS as the primary password authentication
method for console, Telnet, SSH, and/or the WebAgent. (The default
primary
< enable | login >
authentication is
local
.)
<console | telnet | ssh | web>
[< local | none | authorized >]
Provides options for secondary authentication
(default:
none
). Note that for console access, secondary
authentication must be
local
if primary access is not
local
. This prevents you from being locked out of the
switch in the event of a failure in other access methods.
<<web-based | mac-based > login> <chap-radius | peap-mschap v2>:
Password authentication for web-based or mac-based port
access to the switch. Use
peap-mschapv2
when you want pass-
word verification without requiring access to a plain text
password; it is more secure.
Default:
chap-radius
Summary of Contents for HP ProCurve Series 6600
Page 2: ......
Page 6: ...iv ...
Page 26: ...xxiv ...
Page 102: ...2 48 Configuring Username and Password Security Password Recovery ...
Page 204: ...4 72 Web and MAC Authentication Client Status ...
Page 550: ...10 130 IPv4 Access Control Lists ACLs General ACL Operating Notes ...
Page 612: ...12 24 Traffic Security Filters and Monitors Configuring Traffic Security Filters ...
Page 734: ...14 44 Configuring and Monitoring Port Security Operating Notes for Port Security ...
Page 756: ...16 8 Key Management System Configuring Key Chain Management ...
Page 776: ...20 Index web server proxy 14 42 webagent access 6 6 wildcard See ACL wildcard See ACL ...
Page 777: ......