User Authentication
3-61
3
-
Accounting Port Number
– UDP port on authentication server used for
accounting messages. (Range: 1-65535; Default: 1813)
-
Number of Server Transmits
– Number of times the switch tries to authenticate
logon access via the authentication server. (Range: 1-30; Default: 2)
-
Timeout for a reply
– The number of seconds the switch waits for a reply from
the RADIUS server before it resends the request. (Range: 1-65535; Default: 5)
•
RADIUS
Attributes
NAS IP Address
– Specifies the IP address of the Network Access Server
(NAS) to use in the attribute 4 address field in packets sent to the RADIUS
server. (Default: The IP address of the interface that connects the switch to the
RADIUS server.)
The IP address of the interface connecting the switch (i.e., the NAS) to the
RADIUS server is used in the IP headers of RADIUS packets sent to the server.
This address is also used by default in the attribute 4 field inside of RADIUS
packets sent to the server.
It may be necessary for certain AAA processes to configure the attribute 4 field
to an address other than that of the switch’s connecting interface. However,
setting this field to an address other than that of the actual interface connecting
the switch to the RADIUS server will not affect the IP address used inside the IP
headers of RADIUS packets sent from the switch.
Some AAA clients may try to change the attribute 4 address. Setting the NAS IP
address in the attribute 4 field prevents these clients from changing this address.
•
TACACS
Settings
-
Global
– Provides globally applicable settings.
-
Server Index
– Specifies the index number of the server to be configured. The
switch currently supports only one server.
-
Server IP Address
-
Server Port Number
– Network (TCP) port of server used for
authentication messages. (Range: 1-65535; Default: 49)
-
Number of Server Transmits
– Number of times the switch tries to authenticate
logon access via the authentication server. (Range: 1-30; Default: 2)
-
Timeout for a Reply
– The number of seconds the switch waits for a reply from
the RADIUS server before it resends the request. (Range: 1-540; Default: 5)
Note:
The local switch user database has to be set up by manually entering user names
and passwords using the Web or CLI. (See “Configuring User Accounts” on
page 3-58 or “username” on page 4-101)
Summary of Contents for iES4024GP
Page 1: ...iES4028F 4028FP 4024GP ...
Page 4: ...iv This page is intentionally left blank ...
Page 10: ...x This page is intentionally left blank ...
Page 28: ...Contents xxviii This page is intentionally left blank ...
Page 32: ...Tables xxxii This page is intentionally left blank ...
Page 46: ...Introduction 1 10 1 This page is intentionally left blank ...
Page 336: ...Configuring the Switch 3 280 3 This page is intentionally left blank ...
Page 688: ...Command Line Interface 4 352 4 This page is intentionally left blank ...
Page 702: ...Glossary Glossary 8 This page is intentionally left blank ...
Page 710: ...Index 8 Index This page is intentionally left blank ...
Page 711: ...This page is intentionally left blank ...
Page 712: ...iES4028F 4028FP 4024GP ...