18-3
Cisco MDS 9000 Fabric Manager Switch Configuration Guide
OL-7753-01
Chapter 18 Configuring Switch Security
Switch AAA Functionalities
Authentication
Authentication is the process of verifying the identity of the person managing the switch. This identity
verification is based on the user ID and password combination provided by the person trying to manage
the switch. Cisco MDS 9000 Family switches allow you to perform local authentication (using the
lookup database) or remote authentication (using one or more RADIUS or servers).
Authorization
By default, two roles exist in all switches:
•
Network operator (network-operator)—Has permission to view the configuration only. The operator
cannot make any configuration changes.
•
Network administrator (network-admin)—Has permission to execute all commands and make
configuration changes. The administrator can also create and customize up to 64 additional roles.
The two default roles cannot be changed or deleted. You can create additional roles and configure the
following options:
•
Assign user roles either locally or using remote AAA servers.
•
Configure user profiles on a remote AAA server to contain role information. This role information
is automatically downloaded and used when that user is authenticated through remote AAA server.
Accounting
Accounting refers to the log that is kept for each management session in a switch. This information may
be used to generate reports for troubleshooting purposes and user accountability. Accounting can be
implemented locally and remotely.
Remote Authentication by AAA Servers
AAA authentication provides the following advantages over local database authentication:
•
Requires only one password to be shared between the switch and the AAA servers.
•
Easier to manage user password lists for each switch in the fabric.
•
AAA servers are deployed widely across enterprises and can be easily adopted.
Remote Authentication Guidelines
When you prefer using remote C servers, follow these guidelines:
•
A minimum of one AAA server should be IP reachable.
•
If all configured AAA servers are not reachable, the policy configured on the switch determines the
authentication method.
Содержание DS-C9216I-K9
Страница 26: ...Contents xxvi Cisco MDS 9000 Fabric Manager Switch Configuration Guide OL 7753 01 ...
Страница 42: ...xlii Cisco MDS 9000 Fabric Manager Switch Configuration Guide OL 7753 01 New and Changed Information ...
Страница 128: ...10 8 Cisco MDS 9000 Fabric Manager Switch Configuration Guide OL 7753 01 Chapter 10 Managing System Hardware ...