294
Brocade Network Advisor SAN User Manual
53-1002696-01
AAA Settings tab
11
AAA Settings tab
Authentication enables you to configure an authentication server and establish authentication
policies. You can configure the Management application to authenticate users against the local
database (Management application server), an external server (RADIUS, LDAP, or ), or a
switch. Authentication is configured to the local database by default. When you use an external
server, the Management application sends the login information to the external server to make
sure the name and password are valid.
If you configure primary authentication to an external or switch authentication, you can also
configure secondary authentication to the local server. When you log in to the Management
application, if the primary server is unavailable, the Management application attempts with the
next configured primary server. If all primary servers are unavailable, then the Management
application falls back to the secondary authentication. Fall back can occur when the server is
unavailable, authentication fails, or the user is not found.
Configuring Radius server authentication
If you are using a Radius server for authentication, make the following preparations first:
•
Make sure that the server you want to use is on the network that the Management application
manages.
•
Make sure that the external server and its user accounts have been properly configured. For
example, you must define roles and areas of responsibility (AOR) in the external server to
match the Management application roles and AOR.
•
Select an Authentication Type (you will be prompted to provide a type in the Add or Edit Radius
Server dialog box). The Authentication Type is the authentication policy you choose for handling
authentication. The options are PAP and CHAP.
-
PAP, password protected protocol, is based on password verification. Passwords are not
encrypted, and are not secure from eavesdroppers during transmission.
-
CHAP, challenge handshake protocol, uses a three-way handshake method of verification
based on a shared secret. If you are using CHAP, have the shared secret available to you.
You will need to type it in as a configuration parameter.
•
Know the Shared Secret.
•
Have the IP address of the server available.
•
Know the TCP port you are using and make sure it is open in the firewall. For Radius servers,
ports 1812 or 1813 (actually UDP ports) are commonly used. Some older Radius server use
1645 or 1646 instead of 1812 and 1813; check with the Radius server vendor if you are not
sure which port to specify.
•
Know how long you want to wait between attempts to reach the server if it is busy. This is
expressed as a timeout value (default is 3 seconds) in seconds. Values are between 1 and 15.
•
Determine how many attempts (default is 3 times) to make to reach the server before stopping
and assuming it is unreachable. Values are between 1 and 5.
•
If possible, establish an active connection with the Radius server before configuration. This
enables you to test the connection as part of the configuration procedure.
Содержание Network Advisor 12.0.0
Страница 36: ...xxxvi Brocade Network Advisor SAN User Manual 53 1002696 01...
Страница 82: ...34 Brocade Network Advisor SAN User Manual 53 1002696 01 License downgrade 2...
Страница 86: ...38 Brocade Network Advisor SAN User Manual 53 1002696 01 Uninstalling a patch 3...
Страница 122: ...74 Brocade Network Advisor SAN User Manual 53 1002696 01 VM Manager discovery 4...
Страница 184: ...136 Brocade Network Advisor SAN User Manual 53 1002696 01 Fabric tracking 5...
Страница 214: ...166 Brocade Network Advisor SAN User Manual 53 1002696 01 User profiles 6...
Страница 236: ...188 Brocade Network Advisor SAN User Manual 53 1002696 01 Searching for an assigned event filter 7...
Страница 284: ...236 Brocade Network Advisor SAN User Manual 53 1002696 01 User defined performance monitors 8...
Страница 320: ...272 Brocade Network Advisor SAN User Manual 53 1002696 01 Grouping on the topology 9...
Страница 336: ...288 Brocade Network Advisor SAN User Manual 53 1002696 01 Microsoft System Center Operations Manager SCOM plug in 10...
Страница 434: ...386 Brocade Network Advisor SAN User Manual 53 1002696 01 Port Auto Disable 12...
Страница 442: ...394 Brocade Network Advisor SAN User Manual 53 1002696 01 Exporting Host port mapping 13...
Страница 450: ...402 Brocade Network Advisor SAN User Manual 53 1002696 01 Exporting storage port mapping 14...
Страница 536: ...488 Brocade Network Advisor SAN User Manual 53 1002696 01 Virtual FCoE port configuration 16...
Страница 552: ...504 Brocade Network Advisor SAN User Manual 53 1002696 01 Security configuration deployment 17...
Страница 878: ...830 Brocade Network Advisor SAN User Manual 53 1002696 01 Removing thresholds 24...
Страница 922: ...874 Brocade Network Advisor SAN User Manual 53 1002696 01 VLAN routing 26...
Страница 990: ...942 Brocade Network Advisor SAN User Manual 53 1002696 01 SAN Connection utilization 29...
Страница 998: ...950 Brocade Network Advisor SAN User Manual 53 1002696 01 Removing a frame monitor from a switch 30...
Страница 1138: ...1090 Brocade Network Advisor SAN User Manual 53 1002696 01 Call Home Event Tables B...
Страница 1144: ...1096 Brocade Network Advisor SAN User Manual 53 1002696 01 IP Performance monitoring events C...
Страница 1186: ...1138 Brocade Network Advisor SAN User Manual 53 1002696 01 Regular Expressions F...
Страница 1486: ...1438 Brocade Network Advisor SAN User Manual 53 1002696 01 Views H...