data:image/s3,"s3://crabby-images/69484/6948435e999dd7dcebac774158edb7e8ed9af47f" alt="Cisco 6500 - Catalyst Series 10 Gigabit EN Interface Module Expansion Скачать руководство пользователя страница 349"
17-5
Catalyst 6500 Series Switch and Cisco 7600 Series Router Firewall Services Module Configuration Guide using ASDM
OL-20748-01
Chapter 17 Applying AAA for Network Access
Configuring Authentication for Network Access
The following commands authenticate Telnet traffic from the outside interface to a particular server
(209.165.201.5):
hostname(config)#
aaa-server AuthInbound protocol
hostname(config-aaa-server-group)#
exit
hostname(config)#
aaa-server AuthInbound (inside) host 10.1.1.1
hostname(config-aaa-server-host)#
key TACPlusUauthKey
hostname(config-aaa-server-host)#
exit
hostname(config)#
access-list TELNET_AUTH extended permit tcp any host 209.165.201.5
eq
telnet
hostname(config)#
aaa authentication match TELNET_AUTH outside AuthInbound
Configuring Custom Login Prompts
By default, when a user authenticates with the FWSM, they see the following prompt:
•
For HTTP—
HTTP Authentication
.
•
For FTP—
FTP Authentication
.
•
For Telnet—no prompt.
You can customize the login prompt, and also show prompts when a user is accepted or rejected. If you
use a RADIUS server that communicates with a Windows Active Directory server, the reject prompt can
be customized to show when a user was rejected due to invalid credentials (the wrong username or
password) or because a password has expired. If a password expired, the user is prompted for a new
password.
Note
Customizing the login prompt causes the FWSM to use MSCHAPv2 for the user password. Please check
for MSCHAPv2 compatibility with your RADIUS server and back-end database before enabling this
feature.
To customize the login prompt, perform the following steps:
Step 1
To customize the login prompt, enter the following command:
hostname(config)#
auth-prompt prompt
text
Where
text
is a string of up to 235 alphanumeric characters or 31 words, limited by whichever maximum
is first reached. Special characters, spaces, and punctuation characters are permitted. Entering a question
mark or pressing the
Enter
key ends the string. (The question mark appears in the string.)
Step 2
To show text when a user is accepted, enter the following command:
hostname(config)#
auth-prompt accept
text
Step 3
To show text when a user is rejected, enter the following command:
hostname(config)#
auth-prompt reject
text
When you enter the
reject
keyword without the
invalid-credentials
or
reject expired-pwd
keywords,
then this generic prompt is displayed for all rejections that are not due to invalid credentials or expired
passwords. For a rejection due to an invalid credential or an expired password, then the prompt you set
for the
invalid-credentials
or
reject expired-pwd
keyword displays. If you do not set any prompts for
invalid credentials or expired passwords, then the generic reject prompt is shown in all cases.
Step 4
To show text when a user is rejected due to invalid credentials, enter the following command:
Содержание 6500 - Catalyst Series 10 Gigabit EN Interface Module Expansion
Страница 35: ...P A R T 1 Getting Started and General Information ...
Страница 36: ......
Страница 297: ...P A R T 2 Configuring the Security Policy ...
Страница 298: ......
Страница 521: ...P A R T 3 System Administration ...
Страница 522: ......
Страница 613: ...P A R T 4 Reference ...
Страница 614: ......