
54
◆
The switch supports the following authentication services:
■
Authorization of users that access the Telnet, SSH, the web, or console management
interfaces on the switch.
■
Accounting for users that access the Telnet, SSH, the web, or console management
interfaces on the switch.
■
Accounting for IEEE 802.1X authenticated users that access the network through the
switch. This accounting can be used to provide reports, auditing, and billing for services
that users have accessed.
◆
By default, management access is always checked against the authentication database
stored on the local switch. If a remote authentication server is used, you must specify the
authentication method and the corresponding parameters for the remote authentication
protocol on the Network Access Server Configuration page. Local and remote logon
authentication can be used to control management access via Telnet, SSH, a web
browser, or the console interface.
◆
When using RADIUS or logon authentication, the user name and password
must be configured on the authentication server. The encryption methods used for the
authentication process must also be configured or negotiated between the authentication
server and logon client. This switch can pass authentication messages between the
server and client that have been encrypted using MD5 (Message-Digest 5), TLS
(Transport Layer Security), or TTLS (Tunneled Transport Layer Security).
Note: This guide assumes that RADIUS and servers have already been
configured to support AAA. The configuration of RADIUS and server software
is beyond the scope of this guide. Refer to the documentation provided with the RADIUS
and server software.
PARAMETERS
These parameters are displayed:
◆
Client
–
Specifies how the administrator is authenticated when logging into the switch via
Telnet, SSH, a web browser, or the console interface.
◆
Authentication Method
–
Selects the authentication method.
(Options: None, Local, RADIUS, ; Default: Local)
Selecting the option “None” disables access through the specified management interface.
◆
Fallback
–
Uses the local user database for authentication if none of the configured
authentication servers are alive. This is only possible if the Authentication Method is set to
something else than “none” or “local.”
WEB INTERFACE
To configure authentication for management access:
Summary of Contents for GEP-1070
Page 80: ...80 authentication from any point within the network...
Page 168: ...168...