6-13
Catalyst 3550 Multilayer Switch Software Configuration Guide
78-11194-03
Chapter 6 Administering the Switch
Controlling Switch Access with
Configuring
This section describes how to configure your switch to support . At a minimum, you must
identify the host or hosts maintaining the daemon and define the method lists for
authentication. You can optionally define method lists for authorization and accounting. A
method list defines the sequence and methods to be used to authenticate, to authorize, or to keep accounts
on a user. You can use method lists to designate one or more security protocols to be used, thus ensuring
a backup system if the initial method fails. The software uses the first method listed to authenticate, to
authorize, or to keep accounts on users; if that method does not respond, the software selects the next
method in the list. This process continues until there is successful communication with a listed method
or the method list is exhausted.
This section contains this configuration information:
•
Default Configuration, page 6-13
•
Identifying the Server Host and Setting the Authentication Key, page 6-13
•
Configuring Login Authentication, page 6-14
•
Configuring Authorization for Privileged EXEC Access and Network Services, page
6-16
•
Starting Accounting, page 6-17
Default Configuration
and AAA are disabled by default.
To prevent a lapse in security, you cannot configure through a network management
application.When enabled, can authenticate users accessing the switch through the CLI.
Note
Although configuration is performed through the CLI, the server
authenticates HTTP connections that have been configured with a privilege level of 15.
Identifying the Server Host and Setting the Authentication Key
You can configure the switch to use a single server or AAA server groups to group existing server hosts
for authentication. You can group servers to select a subset of the configured server hosts and use them
for a particular service. The server group is used with a global server-host list and contains the list of IP
addresses of the selected server hosts.