1164
PowerConnect B-Series FCX Configuration Guide
53-1002266-01
Configuring TACACS/ security
32
NOTE
You cannot authenticate Brocade Network Advisor (SNMP) access to a Dell PowerConnect device
using TACACS/.
The TACACS and protocols define how authentication, authorization, and accounting
information is sent between a Dell PowerConnect device and an authentication database on a
TACACS/ server. TACACS/ services are maintained in a database, typically on a
UNIX workstation or PC with a TACACS/ server running.
How differs from TACACS
TACACS is a simple UDP-based access control protocol originally developed by BBN for MILNET.
is an enhancement to TACACS and uses TCP to ensure reliable delivery.
is an enhancement to the TACACS security protocol. improves on TACACS by
separating the functions of authentication, authorization, and accounting (AAA) and by encrypting
all traffic between the Dell PowerConnect device and the server. allows for
arbitrary length and content authentication exchanges, which allow any authentication mechanism
to be utilized with the Dell PowerConnect device. is extensible to provide for site
customization and future development features. The protocol allows the Dell PowerConnect device
to request very precise access control and allows the server to respond to each
component of that request.
NOTE
provides for authentication, authorization, and accounting, but an implementation or
configuration is not required to employ all three.
TACACS/ authentication, authorization,
and accounting
When you configure a Dell PowerConnect device to use a TACACS/ server for
authentication
, the device prompts users who are trying to access the CLI for a user name and
password, then verifies the password with the TACACS/ server.
If you are using , Dell recommends that you also configure
authorization
, in which the Dell
PowerConnect device consults a server to determine which management privilege level
(and which associated set of commands) an authenticated user is allowed to use. You can also
optionally configure
accounting
, which causes the device to log information on the server
when specified events occur on the device.
NOTE
By default, a user logging into the device from Telnet or SSH would first enter the User EXEC level.
The user can enter the enable command to get to the Privileged EXEC level.
A user that is successfully authenticated can be automatically placed at the Privileged EXEC level
after login. Refer to
“Entering privileged EXEC mode after a Telnet or SSH login”
on page 1174.
Содержание PowerConnect B-FCXs
Страница 1: ...53 1002266 01 18 March 2011 PowerConnect B Series FCX Configuration Guide ...
Страница 136: ...94 PowerConnect B Series FCX Configuration Guide 53 1002266 01 Viewing information about software licenses 4 ...
Страница 228: ...186 PowerConnect B Series FCX Configuration Guide 53 1002266 01 PowerConnect B Series FCX hitless stacking 5 ...
Страница 229: ...PowerConnect B Series FCX Configuration Guide 187 53 1002266 01 PowerConnect B Series FCX hitless stacking 5 ...
Страница 230: ...188 PowerConnect B Series FCX Configuration Guide 53 1002266 01 PowerConnect B Series FCX hitless stacking 5 ...
Страница 248: ...206 PowerConnect B Series FCX Configuration Guide 53 1002266 01 IPv6 management commands 7 ...
Страница 346: ...304 PowerConnect B Series FCX Configuration Guide 53 1002266 01 802 1s Multiple Spanning Tree Protocol 8 ...
Страница 374: ...332 PowerConnect B Series FCX Configuration Guide 53 1002266 01 Jumbo frame support 9 ...
Страница 424: ...382 PowerConnect B Series FCX Configuration Guide 53 1002266 01 Virtual Switch Redundancy Protocol VSRP 10 ...
Страница 568: ...526 PowerConnect B Series FCX Configuration Guide 53 1002266 01 CLI examples 14 ...
Страница 588: ...546 PowerConnect B Series FCX Configuration Guide 53 1002266 01 Sample application 15 ...
Страница 674: ...632 PowerConnect B Series FCX Configuration Guide 53 1002266 01 Enabling or disabling layer 2 switching 19 ...
Страница 684: ...642 PowerConnect B Series FCX Configuration Guide 53 1002266 01 VLAN based mirroring 20 ...
Страница 724: ...682 PowerConnect B Series FCX Configuration Guide 53 1002266 01 Reading CDP packets 23 ...
Страница 768: ...726 PowerConnect B Series FCX Configuration Guide 53 1002266 01 Clearing cached LLDP neighbor information 24 ...
Страница 930: ...888 PowerConnect B Series FCX Configuration Guide 53 1002266 01 26 ...
Страница 948: ...906 PowerConnect B Series FCX Configuration Guide 53 1002266 01 Configuring MLD snooping 27 ...
Страница 962: ...920 PowerConnect B Series FCX Configuration Guide 53 1002266 01 Displaying CPU utilization statistics 28 ...
Страница 1022: ...980 PowerConnect B Series FCX Configuration Guide 53 1002266 01 Displaying OSPF information 29 ...
Страница 1142: ...1100 PowerConnect B Series FCX Configuration Guide 53 1002266 01 Clearing diagnostic buffers 30 ...
Страница 1258: ...1216 PowerConnect B Series FCX Configuration Guide 53 1002266 01 Using Secure copy with SSH2 33 ...
Страница 1314: ...1272 PowerConnect B Series FCX Configuration Guide 53 1002266 01 Displaying port security information 35 ...
Страница 1348: ...1306 PowerConnect B Series FCX Configuration Guide 53 1002266 01 Example configurations 36 ...
Страница 1406: ...1364 PowerConnect B Series FCX Configuration Guide 53 1002266 01 IP source guard 39 ...
Страница 1422: ...1380 PowerConnect B Series FCX Configuration Guide 53 1002266 01 SNMP v3 Configuration examples 40 ...