18-10
Cisco MDS 9000 Fabric Manager Switch Configuration Guide
OL-7753-01
Chapter 18 Configuring Switch Security
Authentication and Authorization Process
Figure 18-1
Switch Authorization and Authentication Flow
Step 1
When you can log in to the required switch in the Cisco MDS 9000 Family, you have the option to use
the Telnet, SSH, or Console login options.
Step 2
When you configure server groups using the server group authentication method, an authentication
request is sent to the first AAA server in the group.
•
If the AAA server fails to respond, then the next AAA server will be tried and so on until the remote
server responds to the authentication request.
•
If all AAA servers in the server group fail to respond, then the servers in the next server group are
tried.
•
If all configured methods fails, then local database is used for authentication.
Access
permitted
Access
permitted
Start
Incoming
access
request to
switch
Local user
name only
Local
database
lookup
First or
next server
group
lookup
First or
next server
lookup
Denied
access
Denied
access
Access
permitted
Radius
lookup
lookup
No response
No response
Failure
Failure
Accept
Accept
Failure
Failure
Success
Success
None
Local
105229
No more server
groups left
Found a server group
Found a RADIUS server
Found a server
No more ser
v
ers left
Содержание DS-C9216I-K9
Страница 26: ...Contents xxvi Cisco MDS 9000 Fabric Manager Switch Configuration Guide OL 7753 01 ...
Страница 42: ...xlii Cisco MDS 9000 Fabric Manager Switch Configuration Guide OL 7753 01 New and Changed Information ...
Страница 128: ...10 8 Cisco MDS 9000 Fabric Manager Switch Configuration Guide OL 7753 01 Chapter 10 Managing System Hardware ...