Security
7950 SR OS System Management Guide
Page 139
authentication-order
Syntax
authentication-order
[
method-1
]
[
method-2
] [
method-3
] [
exit-on-reject
]
no authentication-order
Context
config>system>security>password
Description
This command configures the sequence in which password authentication, authorization, and
accounting is attempted among RADIUS, , and local passwords.
The order should be from the most preferred authentication method to the least preferred. The pres-
ence of all methods in the command line does not guarantee that they are all operational. Specifying
options that are not available delays user authentication.
If all (operational) methods are attempted and no authentication for a particular login has been
granted, then an entry in the security log register the failed attempt. Both the attempted login identifi-
cation and originating IP address is logged with the a timestamp.
The
no
form of the command reverts to the default authentication sequence.
Default
authentication-order radius tacplus local
- The preferred order for password authentication is 1.
RADIUS, 2. and 3. local passwords.
Parameters
method-1 —
The first password authentication method to attempt.
Default
radius
Values
radius, tacplus, local
method-2 —
The second password authentication method to attempt.
Default
tacplus
Values
radius, tacplus, local
method-3 —
The third password authentication method to attempt.
Default
local
Values
radius, tacplus, local
radius —
RADIUS authentication.
tacplus —
authentication.
local —
Password authentication based on the local password database.
exit-on-reject —
When enabled and if one of the AAA methods configured in the authentication
order sends a reject, then the next method in the order will not be tried. If the
exit-on-reject
keyword is not specified and if one AAA method sends a reject, the next AAA method will be
attempted. If in this process, all the AAA methods are exhausted, it will be considered as a reject.
Note that a rejection is distinct from an unreachable authentication server. When the
exit-on-
reject
keyword is specified, authorization and accounting will only use the method that provided
an affirmation authentication; only if that method is no longer readable or is removed from the
configuration will other configured methods be attempted. If the local keyword is the first
authentication and:
Содержание 7950 SR
Страница 10: ...Page 10 7950 SR OS System Management Guide List of Figures...
Страница 14: ...About This Guide Page 14 7950 SR OS System Management Guide...
Страница 16: ...Alcatel Lucent 7950 SR Router Configuration Process Page 16 7950 SR OS System Management Guide...
Страница 56: ...Configuration Notes Page 56 7950 SR OS System Management Guide...
Страница 88: ...Configuring Login Controls Page 88 7950 SR OS System Management Guide...
Страница 106: ...Security Command Reference Page 106 7950 SR OS System Management Guide...
Страница 206: ...Distributed CPU Protection Commands Page 206 7950 SR OS System Management Guide...
Страница 244: ...Debug Commands Page 244 7950 SR OS System Management Guide...
Страница 254: ...Configuration Notes Page 254 7950 SR OS System Management Guide...
Страница 276: ...SNMP Security Commands Page 276 7950 SR OS System Management Guide...
Страница 296: ...Show Commands Page 296 7950 SR OS System Management Guide...
Страница 322: ...Configuration Notes Page 322 7950 SR OS System Management Guide...
Страница 358: ...Log Management Tasks Page 358 7950 SR OS System Management Guide...
Страница 454: ...Facility Alarm List Page 454 7950 SR OS System Management Guide...
Страница 460: ...Standards and Protocols Page 460 Standards and Protocols...