C
ONFIGURING
THE
S
WITCH
2-16
CLI
– Assign a user name to access-level 15 (i.e., administrator),
then specify the password.
Configuring RADIUS/ Logon Authentication
You can configure this switch to authenticate users logging into
the system for management access using local, RADIUS, or
authentication methods.
RADIUS and are logon authentication protocols that use
software running on a central server to control access to
RADIUS-aware or -aware devices on the network. An
authentication server contains a database of multiple user name/
password pairs with associated privilege levels for each user that
requires management access to a switch.
Like RADIUS, Terminal Access Controller Access Control System
Plus () is a system that uses a central server to control
authentication for access to switches on the network.
RADIUS uses UDP while uses TCP. UDP only offers best
effort delivery, while TCP offers a connection-oriented transport.
Also, note that RADIUS encrypts only the password in the
access-request packet from the client to the server, while
encrypts the entire body of the packet.
Command Usage
•
By default, management access is always checked against the
authentication database stored on the local switch. If a remote
authentication server is used, you must specify the
authentication sequence and the corresponding parameters for
the remote authentication protocol.
Console(config)#username bob access-level 15
3-30
Console(config)#username bob password 0 smith
Console(config)#
b_mgmt.book Page 16 Tuesday, July 8, 2003 5:24 PM
Summary of Contents for 8612T - annexe 1
Page 2: ......
Page 32: ...SWITCH MANAGEMENT 1 18 ...
Page 167: ...801 1X PORT AUTHENTICATION 2 135 ...
Page 168: ...CONFIGURING THE SWITCH 2 136 ...
Page 362: ...GLOSSARY Glossary 8 ...
Page 365: ......