Instruction Manual
97
Configuring AAA on the Managed Switch:
1. Configure RADIUS and server access parameters. See “Configuring Local/
Remote Logon Authentication”.
2. Define RADIUS and server groups to support the accounting and
authorization of services.
3. Define a method name for each service to which you want to apply accounting or
authorization and specify the RADIUS or server groups to use. Apply the
method names to port or line interfaces.
Access
This section enables you to control remote access to the Switch, including the different
access methods. From this section you can control:
•
Telnet
•
SSH
•
HTTP
•
HTTPS
Managed Access Method
This section enables you to define the rules for accessing the switch. From this section
you can define:
• Profile Rules
• Access Rules
DHCP Snooping
The addresses assigned to DHCP clients on unsecure ports can be carefully
controlled using the dynamic bindings registered with DHCP Snooping. DHCP
snooping allows a switch to protect a network from rogue DHCP servers or other
devices which send port-related information to a DHCP server. This information
can be useful in tracking an IP address back to a physical port.
Command Usage
•
Network traffic may be disrupted when malicious DHCP messages are received
from an outside source. DHCP snooping is used to filter DHCP messages
received on a non-secure interface from outside the network or firewall. When
DHCP snooping is enabled globally and enabled on a VLAN interface, DHCP