RADIUS Authentication and Accounting
Configuring the Switch for RADIUS Authentication
radius
(or
tacacs
) for primary authentication, you must configure
local
for the
secondary method. This prevents the possibility of being completely locked
out of the switch in the event that all primary access methods fail.
Syntax:
aaa authentication < console | telnet | ssh | web > < enable | login > radius
Configures RADIUS as the primary password authentication
method for console, Telnet, SSH, and/or the web browser interface.
(The default primary
< enable | login >
authentication is
local
.)
[< local | none >]
Provides options for secondary authentication
(default:
none
). Note that for console access, secondary
authentication must be
local
if primary access is not
local
. This prevents you from being locked out of the
switch in the event of a failure in other access methods.
For example, suppose you already configured local passwords on the switch,
but want RADIUS to protect primary Telnet and SSH access without allowing
a secondary Telnet or SSH access option (the switch’s local passwords):
The switch now
allows Telnet and
SSH authentication
only through
RADIUS.
Note:
The
Webui
access task shown
in this figure is
available only on the
switches covered in
this guide.
Figure 6-2. Example Configuration for RADIUS Authentication
N o t e
If you configure the Login Primary method as
local
instead of
radius
(and local
passwords are configured on the switch), then clients connected to your
network can gain access to either the Operator or Manager level without
encountering the RADIUS authentication specified for Enable Primary. Refer
to “Local Authentication Process” on page 6-19.
6-11
Summary of Contents for J8697A
Page 1: ...6200yl Access Security Guide 5400zl 3500yl ProCurve Switches K 11 XX www procurve com ...
Page 2: ......
Page 22: ...Product Documentation Feature Index xx ...
Page 55: ...Configuring Username and Password Security Front Panel Security 2 21 ...
Page 56: ...Configuring Username and Password Security Front Panel Security 2 22 ...
Page 58: ...Virus Throttling Contents Operating Notes 3 30 Connection Rate Log and Trap Messages 3 31 3 2 ...
Page 88: ...Virus Throttling Connection Rate Log and Trap Messages This page is intentionally unused 3 32 ...
Page 118: ...Web and MAC Authentication Client Status This page intentionally unused 4 30 ...
Page 356: ...Configuring and Monitoring Port Security Operating Notes for Port Security 11 44 ...
Page 370: ...Using Authorized IP Managers Operating Notes This page is intentionally unused 12 14 ...
Page 388: ...10 Index ...
Page 389: ......