i
Table of Contents
1 AAA Configuration ····································································································································1-1
Introduction to AAA ·································································································································1-1
Introduction to RADIUS···························································································································1-2
Client/Server Model ·························································································································1-3
Security and Authentication Mechanisms ·······················································································1-3
Basic Message Exchange Process of RADIUS ··············································································1-3
RADIUS Packet Format···················································································································1-4
Extended RADIUS Attributes ··········································································································1-7
Introduction to HWTACACS····················································································································1-8
Differences Between HWTACACS and RADIUS ············································································1-8
Basic Message Exchange Process of HWTACACS ·······································································1-9
Domain-Based User Management········································································································1-10
Protocols and Standards·······················································································································1-11
AAA Configuration Task List ·················································································································1-11
AAA Configuration Task List ·········································································································1-12
RADIUS Configuration Task List ···································································································1-13
HWTACACS Configuration Task List ····························································································1-13
Configuring AAA····································································································································1-14
Configuration Prerequisites ···········································································································1-14
Creating an ISP Domain················································································································1-14
Configuring ISP Domain Attributes································································································1-15
Configuring AAA Authentication Methods for an ISP Domain·······················································1-15
Configuring AAA Authorization Methods for an ISP Domain ························································1-17
Configuring AAA Accounting Methods for an ISP Domain····························································1-19
Configuring Local User Attributes··································································································1-21
Configuring User Group Attributes ································································································1-22
Tearing down User Connections Forcibly ·····················································································1-23
Configuring a NAS ID-VLAN Binding ····························································································1-23
Displaying and Maintaining AAA ···································································································1-24
Configuring RADIUS ·····························································································································1-24
Creating a RADIUS Scheme ·········································································································1-25
Specifying the RADIUS Authentication/Authorization Servers······················································1-25
Specifying the RADIUS Accounting Servers and Relevant Parameters·······································1-26
Setting the Shared Key for RADIUS Packets················································································1-27
Setting the Upper Limit of RADIUS Request Retransmission Attempts ·······································1-28
Setting the Supported RADIUS Server Type ················································································1-28
Setting the Status of RADIUS Servers ··························································································1-29
Configuring Attributes Related to Data to Be Sent to the RADIUS Server ···································1-30
Enabling the RADIUS Trap Function·····························································································1-30
Specifying the Source IP Address for RADIUS Packets to Be Sent ·············································1-31
Setting Timers Regarding RADIUS Servers··················································································1-31
Specifying a Security Policy Server·······························································································1-32
Enabling the Listening Port of the RADIUS Client ········································································1-33
Содержание S7906E - Switch
Страница 82: ...1 4 DeviceA interface tunnel 1 DeviceA Tunnel1 service loopback group 1...
Страница 200: ...1 11 DeviceB display vlan dynamic No dynamic vlans exist...
Страница 494: ...ii Displaying and Maintaining Tunneling Configuration 1 45 Troubleshooting Tunneling Configuration 1 45...
Страница 598: ...ii...
Страница 1757: ...4 9...
Страница 1770: ...6 4...
Страница 2017: ...2 11 Figure 2 3 SFTP client interface...
Страница 2062: ...i Table of Contents 1 URPF Configuration 1 1 URPF Overview 1 1 What is URPF 1 1 How URPF Works 1 1 Configuring URPF 1 2...
Страница 2238: ...1 16 DeviceA cfd linktrace service instance 1 mep 1001 target mep 4002...
Страница 2442: ...2 4 Set the interval for sending Syslog or trap messages to 20 seconds Device mac address information interval 20...