RADIUS Authentication and Accounting
Commands Authorization
Example Configuration on Cisco Secure ACS for MS Windows
It is necessary to create a dictionary file that defines the VSAs so that the
RADIUS server application can determine which VSAs to add to its user
interface. The VSAs will appear below the standard attributes that can be
configured in the application.
The dictionary file must be placed in the proper directory on the RADIUS
server. Follow these steps.
1. Create a dictionary file (for example, hp.ini) containing the HP VSA
definitions, as shown in the example below.
;[User Defined Vendor]
;
; The Name and IETF vendor code and any VSAs MUST be unique.
;
; One or more VSAs named (max 255)
;
; Each named VSA requires a definition section…
;
; Types are STRING, INTEGER, IPADDR
;
; The profile specifies usage, IN for accounting, OUT for
authorization,
; MULTI if more than a single instance is allowed per
RADIUS message.
; Combinations are allowed, e.g. "IN", "MULTI OUT",
"MULT IN OUT"
;
; Enumerations are optional for INTEGER attribute types
[User Defined Vendor]
Name=HP
IETF Code=11
VSA 2=Hp-Command-String
VSA 3=Hp-Command-Exception
[Hp-Command-String]
Type=STRING
Profile=IN OUT
[Hp-Command-Exception]
Type=INTEGER
5-30
Summary of Contents for PROCURVE 2910AL
Page 1: ...Access Security Guide ProCurve Switches W 14 03 2910al www procurve com ...
Page 2: ......
Page 3: ...HP ProCurve 2910al Switch February 2009 W 14 03 Access Security Guide ...
Page 84: ...Configuring Username and Password Security Front Panel Security 2 36 ...
Page 156: ...TACACS Authentication Operating Notes 4 30 ...
Page 288: ...Configuring Secure Socket Layer SSL Common Errors in SSL setup 8 22 ...
Page 416: ...Configuring Advanced Threat Protection Using the Instrumentation Monitor 10 28 ...
Page 572: ...Using Authorized IP Managers Operating Notes 14 14 ...
Page 592: ...12 Index ...
Page 593: ......