Chapter 12
| Security Measures
AAA (Authentication, Authorization and Accounting)
– 270 –
■
TACACS
– User authentication is performed using a server only.
■
[authentication sequence] – User authentication is performed by up to
three authentication methods in the indicated sequence.
Web Interface
To configure the method(s) of controlling management access:
1.
Click Security, AAA, System Authentication.
2.
Specify the authentication sequence (i.e., one to three methods).
3.
Click Apply.
Figure 160: Configuring the Authentication Sequence
Configuring
Remote Logon
Authentication
Servers
Use the Security > AAA > Server page to configure the message exchange
parameters for RADIUS or remote access authentication servers.
Remote Authentication Dial-in User Service (RADIUS) and Terminal Access
Controller Access Control System Plus () are logon authentication
protocols that use software running on a central server to control access to RADIUS-
aware or TACACS-aware devices on the network. An authentication server contains
a database of multiple user name/password pairs with associated privilege levels
for each user that requires management access to the switch.
Figure 161: Authentication Server Operation
RADIUS uses UDP while uses TCP. UDP only offers best effort delivery,
while TCP offers a more reliable connection-oriented transport. Also, note that
Web
Telnet
RADIUS/
server
console
1. Client attempts management access.
2. Switch contacts authentication server.
3. Authentication server challenges client.
4. Client responds with proper password or key.
5. Authentication server approves access.
6. Switch grants management access.
Summary of Contents for GTL-2881
Page 34: ...Section I Getting Started 34 ...
Page 48: ...Section II Web Configuration 48 Unicast Routing on page 651 ...
Page 151: ...Chapter 4 Interface Configuration VLAN Trunking 151 Figure 69 Configuring VLAN Trunking ...
Page 152: ...Chapter 4 Interface Configuration VLAN Trunking 152 ...
Page 230: ...Chapter 8 Congestion Control Automatic Traffic Control 230 ...
Page 596: ...Chapter 14 Multicast Filtering Multicast VLAN Registration for IPv6 596 ...
Page 620: ...Chapter 15 IP Configuration Setting the Switch s IP Address IP Version 6 620 ...
Page 672: ...Section III Appendices 672 ...
Page 678: ...Appendix A Software Specifications Management Information Bases 678 ...
Page 688: ...Appendix C License Statement GPL Code Statement Notification of Compliance 688 ...
Page 696: ...Glossary 696 ...
Page 706: ...GTL 2881 GTL 2882 E112016 ST R01 ...