![Dell PowerConnect M6220 Скачать руководство пользователя страница 186](http://html.mh-extra.com/html/dell/powerconnect-m6220/powerconnect-m6220_user-configuration-manual_84547186.webp)
186
Configuring Authentication, Authorization, and Accounting
profiles have an implicit “deny all” rule, such that any command that does
not match any rule in the profile is considered to have been denied by that
profile.
A user can be assigned to more than one profile. If there are conflicting rules
in profiles, the “permit” rule always takes precedence over the “deny” rule.
That is, if any profile assigned to a user permits a command, then the user is
permitted access to that command. A user may be assigned up to 16 profiles.
A number of profiles are provided by default. These profiles cannot be altered
by the switch administrator. See "Administrative Profiles" on page 204 for the
list of default profiles.
If the successful authorization method does not provide an administrative
profile for a user, then the user is permitted access based upon the user's
privilege level. This means that, if a user successfully passes enable
authentication or if exec authorization assigns a privilege level, the user is
permitted access to all commands. This is also true if none of the
administrative profiles provided are configured on the switch. If some, but
not all, of the profiles provided in the authentication are configured on the
switch, then the user is assigned the profiles that exist, and a message is
logged that indicates which profiles could not be assigned.
Accounting
Accounting is used to record security events, such as a user logging in or
executing a command. Accounting records may be sent upon completion of
an event (stop-only) or at both the beginning and end of an event (start-
stop). There are three types of accounting: commands, dot1x, and exec.
•
Commands
—Sends accounting records for command execution.
•
Dot1x
—Sends accounting records for network access.
•
Exec
—Sends accounting records for management access (logins).
For more information about the data sent in accounting records, see "Which
RADIUS Attributes Does the Switch Support?" on page 198 and "Using
Servers to Control Management Access" on page 201.
Table 9-4 shows the valid methods for each type of accounting:
Содержание PowerConnect M6220
Страница 52: ...52 Introduction ...
Страница 86: ...86 Switch Features ...
Страница 100: ...100 Hardware Overview ...
Страница 116: ...116 Using the Command Line Interface ...
Страница 121: ...Default Settings 121 ...
Страница 122: ...122 Default Settings ...
Страница 142: ...142 Setting Basic Network Information ...
Страница 206: ...206 Configuring Authentication Authorization and Accounting ...
Страница 292: ...292 Managing General System Settings Figure 11 31 Verify MOTD ...
Страница 296: ...296 Managing General System Settings ...
Страница 332: ...332 Configuring SNMP ...
Страница 408: ...408 Monitoring Switch Traffic ...
Страница 560: ...560 Configuring Access Control Lists ...
Страница 582: ...582 Configuring VLANs Figure 21 6 Add Ports to VLAN 4 Click Apply 5 Verify that the ports have been added to the VLAN ...
Страница 591: ...Configuring VLANs 591 Figure 21 17 GVRP Port Parameters Table ...
Страница 597: ...Configuring VLANs 597 Figure 21 24 Double VLAN Port Parameter Table ...
Страница 693: ...Configuring Port Based Traffic Control 693 Figure 24 3 Storm Control 5 Click Apply ...
Страница 780: ...780 Configuring Connectivity Fault Management ...
Страница 804: ...804 Snooping and Inspecting Traffic Figure 27 17 DAI Interface Configuration Summary ...
Страница 818: ...818 Snooping and Inspecting Traffic ...
Страница 836: ...836 Configuring Link Aggregation ...
Страница 860: ...860 Configuring Data Center Bridging Features ...
Страница 906: ...906 Configuring DHCP Server Settings ...
Страница 940: ...940 Configuring L2 and L3 Relay Features Figure 34 3 DHCP Relay Interface Summary ...
Страница 1080: ...1080 Configuring VRRP ...
Страница 1104: ...1104 Configuring IPv6 Routing ...
Страница 1124: ...1124 Configuring DHCPv6 Server and Relay Settings Relay Interface Number Vl100 Relay Remote ID Option Flags ...
Страница 1131: ...Configuring Differentiated Services 1131 Figure 40 5 DiffServ Class Criteria ...
Страница 1158: ...1158 Configuring Class of Service Figure 41 1 Mapping Table Configuration CoS 802 1P ...
Страница 1174: ...1174 Configuring Auto VoIP Figure 42 2 Auto VoIP Interface Configuration ...
Страница 1240: ...1240 Managing IPv4 and IPv6 Multicast Figure 43 51 DVMRP Next Hop Summary ...
Страница 1266: ...1266 Managing IPv4 and IPv6 Multicast ...
Страница 1274: ...1274 System Process Definitions ...
Страница 1294: ...1294 Index ...