User Authentication
3-65
3
- Confirm Secret Text String
– Re-type the string entered in the previous field to
ensure no errors were made. The switch will not change the encryption key if
these two fields do not match.
- Change
– Clicking this button adds or modifies the selected encryption key.
Web
– Click Security, Encryption Key. Choose the appropriate RADIUS or
ServerIndex, enter Secret Text String and confirm it, then click Change.
Figure 3-34 Encryption Key Settings
CLI
– This example sets a global encryption key for RADIUS and TACACS servers.
AAA Authorization and Accounting
The Authentication, authorization, and accounting (AAA) feature provides the main
framework for configuring access control on the switch. The three security functions
can be summarized as follows:
• Authentication — Identifies users that request access to the network.
• Authorization — Determines if users can access specific services.
• Accounting — Provides reports, auditing, and billing for services that users have
accessed on the network.
The AAA functions require the use of configured RADIUS or servers in
the network. The security servers can be defined as sequential groups that are then
applied as a method for controlling user access to specified services. For example,
when the switch attempts to authenticate a user, a request is sent to the first server
in the defined group, if there is no response the second server will be tried, and so
on. If at any point a pass or fail is returned, the process stops.
The switch supports the following AAA features:
• Accounting for IEEE 802.1X authenticated users that access the network through
the switch.
Console(config)#radius-server key green
Console(config)#tacacs-server key green
Console(config)#
Summary of Contents for iES4028F
Page 1: ...iES4028F 4028FP 4024GP ...
Page 4: ...iv This page is intentionally left blank ...
Page 10: ...x This page is intentionally left blank ...
Page 28: ...Contents xxviii This page is intentionally left blank ...
Page 32: ...Tables xxxii This page is intentionally left blank ...
Page 46: ...Introduction 1 10 1 This page is intentionally left blank ...
Page 336: ...Configuring the Switch 3 280 3 This page is intentionally left blank ...
Page 688: ...Command Line Interface 4 352 4 This page is intentionally left blank ...
Page 702: ...Glossary Glossary 8 This page is intentionally left blank ...
Page 710: ...Index 8 Index This page is intentionally left blank ...
Page 711: ...This page is intentionally left blank ...
Page 712: ...iES4028F 4028FP 4024GP ...