18-7
Cisco MDS 9000 Fabric Manager Switch Configuration Guide
OL-7753-01
Chapter 18 Configuring Switch Security
Configuring
•
accountinginfo—This attribute stores additional accounting information besides the attributes
covered by a standard RADIUS accounting protocol. This attribute is only sent in the VSA portion
of the Account-Request frames from the RADIUS client on the switch, and it can only be used with
the accounting protocol value.
Configuring
A Cisco MDS switch uses the Terminal Access Controller Access Control System plus ()
protocol to communicate with remote AAA servers. You can configure multiple servers and
set timeout values.
This section contains the following topics:
•
About , page 18-7
•
Advantages of , page 18-7
•
Enabling , page 18-8
•
Setting the Server Address, page 18-8
•
Setting the Secret Key, page 18-8
•
Setting the Timeout Value, page 18-8
•
Defining Custom Attributes for Roles, page 18-8
About
is a client-server protocol which uses TCP (TCP port 49) for transport requirements. All
switches in the Cisco MDS 9000 Family provide centralized authentication using the
protocol. The addition of support in SAN-OS 1.3(x) enables the following advantages over
RADIUS authentication:
•
Provides independent, modular AAA facilities--authorization can be done without authentication.
•
Performs independent of servers if it is configured to its own database.
•
TCP transport protocol to send data between the AAA client and server, using reliable transfers with
a connection-oriented protocol
•
Encrypts the entire protocol payload between the switch and the AAA server to ensure higher data
confidentiality--the RADIUS protocol only encrypts passwords.
Advantages of
This section provides a brief list of advantages that has over and RADIUS.
•
Uses TCP protocol which has a connection-oriented transport
•
Provides built-in transport support
•
Provides a separate acknowledgment that a request has been received
•
Provides immediate indication of a crashed, or not running, server
•
Detects server crashes out-of-band with actual requests
Содержание DS-C9216I-K9
Страница 26: ...Contents xxvi Cisco MDS 9000 Fabric Manager Switch Configuration Guide OL 7753 01 ...
Страница 42: ...xlii Cisco MDS 9000 Fabric Manager Switch Configuration Guide OL 7753 01 New and Changed Information ...
Страница 128: ...10 8 Cisco MDS 9000 Fabric Manager Switch Configuration Guide OL 7753 01 Chapter 10 Managing System Hardware ...