
Access Service Security 4-11
Defining Authentication Method Lists
Enter the aaa authentication Command
To define an authentication method list, start by entering the aaa authentication global
configuration command, as shown in the following example:
5300# configure terminal
5300(config)# aaa authentication
Specify Protocol or Login Authentication
After you enter aaa authentication, you must specify one of the following dial-in protocols as
applicable for your network:
•
If you are enabling dial-in PPP access, specify ppp
•
If you are enabling dial-in ARA access, specify arap
•
If you are enabling users to connect to the EXEC facility, specify login
You can specify only one dial-in protocol per authentication method list. However, you can create
multiple authentication method lists with each of these options. You must give each list a different
name, as described in the next section “Identify a List Name.”
If you specify the ppp option, the default authentication method for PPP is PAP. For greater security,
specify CHAP. The full command is aaa authentication ppp chap. For example:
5300# configure terminal
5300(config)# aaa authentication ppp
If you specify the arap option, the authentication method built into ARA is used. The full command
is aaa authentication arap.
Identify a List Name
A list name identifies each authentication list. You can choose either to use the keyword default, or
choose any other name that describes the authentication list. For example, you might give it the name
ppp-radius if you intend to apply it to interfaces configured for PPP and RADIUS authentication.
The list name can be any alphanumeric string. The default method list is automatically applied to
all lines and interfaces. Named method lists must be applied to specific lines or interfaces.
You can create different authentication method lists and apply them to lines and interfaces
selectively. You can even create a named authentication method list that you do not apply to a line
or interface, but which you intend to apply at some later point, such as when you deploy a new login
method for users.
After you define a list name, you must identify additional security attributes (such as local
authentication versus or RADIUS).
In the following example, the default authentication method list for PPP dial-in clients uses the local
security database:
5300# configure terminal
5300(config)# aaa authentication ppp default
In the following example, the PPP authentication method list name is insecure:
5300# configure terminal
5300(config)# aaa authentication ppp insecure
Содержание AS5300 - Universal Access Server
Страница 4: ......
Страница 10: ...x Book Title ...
Страница 34: ...Where to Go Next Cisco AS5300 Universal Access Server Software Configuration Guide 2 6 ...
Страница 160: ...Cisco AS5300 Universal Access Server Software Configuration Guide ROM Monitor Commands B 8 ...
Страница 184: ...Cisco AS5300 Universal Access Server Software Configuration Guide Where to Go Next C 24 ...
Страница 192: ...Cisco AS5300 Universal Access Server Software Configuration Guide New Hardware Features D 8 ...