9-63
Cisco MGX 8850 (PXM1E/PXM45), Cisco MGX 8950, Cisco MGX 8830, and Cisco MGX 8880 Configuration Guide
Release 5.0.10, OL-3845-01 Rev. B0, August 16, 2004
Chapter 9 Switch Operating Procedures
Managing Remote () Authentication and Authorization
Returning to the Previous Session
After you create a secure session between two switches, enter the bye command or the exit command to
close the current session and return to the previous session. The following example shows the switch
response to the bye command:
M8850_LA.8.PXM.a >
bye
(session ended)
Connection to 172.29.52.88 closed by remote host.
Connection to 172.29.52.88 closed.
M8850_NY.7.PXM.a >
Managing Remote () Authentication and Authorization
Remote authentication and authorization is a feature that allows you to manage user authentication and
command authorization on multiple switches from a single authentication, authorization, and accounting
(AAA) server. Authentication verifies that a user is entitled to connect to a switch, and authorization
verifies that the user is entitled to execute each command the user enters. Communications between the
switch and the AAA server use the Terminal Access Control Access Control System Plus ()
protocol. To configure remote authentication and authorization, you need to do the following:
1.
Configure AAA servers
2.
Configure the Cisco MGX switch to access the AAA servers
3.
Configure the default privilege level
4.
Configure the prompt override option
5.
Configure authentication on the switch
6.
Configure authorization on the switch
The following sections describe how to perform these tasks and other tasks related to managing AAA
server authentication.
Configuring AAA Servers
To configure a Cisco MGX switch for remote authentication and authorization, you must
have an IP address for the remote AAA server. For encrypted authentication and authorization, you must
also have an encrypted key to apply at the AAA server and at the Cisco MGX switch.
Tip
If you know the encryption key and the IP address the AAA server will use, you can configure the server
after the switch. The “
Configuring User Authentication on the Switch
” and “
” sections describe the authentication and authorization that take place when
the AAA server is not available.