RADIUS Authentication and Accounting
Configuring the Switch for RADIUS Authentication
Figure 5-3. Example Configuration for RADIUS Authentication
The switch now
allows Telnet and
SSH authentication
only through
RADIUS.
Note:
The
Webui
access task shown
in this figure is
available only on the
switches covered in
this guide.
N o t e
If you configure the Login Primary method as
local
instead of
radius
(and local
passwords are configured on the switch), then clients connected to your
network can gain access to either the Operator or Manager level without
encountering the RADIUS authentication specified for Enable Primary. Refer
to “Local Authentication Process” on page 5-24.
2. Enable the (Optional) Access Privilege Option
In the default RADIUS operation, the switch automatically admits any authen
ticated client to the Login (Operator) privilege level, even if the RADIUS server
specifies Enable (Manager) access for that client. Thus, an authenticated user
authorized for the Manager privilege level must authenticate again to change
privilege levels. Using the optional
login privilege-mode
command overrides
5-13
Summary of Contents for PROCURVE 2910AL
Page 1: ...Access Security Guide ProCurve Switches W 14 03 2910al www procurve com ...
Page 2: ......
Page 3: ...HP ProCurve 2910al Switch February 2009 W 14 03 Access Security Guide ...
Page 84: ...Configuring Username and Password Security Front Panel Security 2 36 ...
Page 156: ...TACACS Authentication Operating Notes 4 30 ...
Page 288: ...Configuring Secure Socket Layer SSL Common Errors in SSL setup 8 22 ...
Page 416: ...Configuring Advanced Threat Protection Using the Instrumentation Monitor 10 28 ...
Page 572: ...Using Authorized IP Managers Operating Notes 14 14 ...
Page 592: ...12 Index ...
Page 593: ......