![Digisol DG-FS4528P Скачать руководство пользователя страница 158](http://html1.mh-extra.com/html/digisol/dg-fs4528p/dg-fs4528p_management-manual_2498025158.webp)
C
HAPTER
7
| Security Measures
Configuring Local/Remote Logon Authentication
– 158 –
Figure 50: Authentication Server Operation
RADIUS uses UDP while uses TCP. UDP only offers best effort
delivery, while TCP offers a connection-oriented transport. Also, note that
RADIUS encrypts only the password in the access-request packet from the
client to the server, while encrypts the entire body of the packet.
C
OMMAND
U
SAGE
By default, management access is always checked against the
authentication database stored on the local switch. If a remote
authentication server is used, you must specify the authentication
sequence and the corresponding parameters for the remote
authentication protocol. Local and remote logon authentication control
management access via the console port, web browser, or Telnet.
RADIUS and logon authentication assign a specific privilege
level for each user name/password pair. The user name, password, and
privilege level must be configured on the authentication server. The
encryption methods used for the authentication process must also be
configured or negotiated between the authentication server and logon
client. This switch can pass authentication messages between the
server and client that have been encrypted using MD5 (Message-Digest
5), TLS (Transport Layer Security), or TTLS (Tunneled Transport Layer
Security).
You can specify up to three authentication methods for any user to
indicate the authentication sequence. For example, if you select (1)
RADIUS, (2) TACACS and (3) Local, the user name and password on
the RADIUS server is verified first. If the RADIUS server is not
available, then authentication is attempted using the server,
and finally the local user name and password is checked.
P
ARAMETERS
These parameters are displayed:
Authentication Sequence
– Select the authentication, or
authentication sequence required:
Local
– User authentication is performed only locally by the switch.
Web
Telnet
RADIUS/
server
console
1. Client attempts management access.
2. Switch contacts authentication server.
3. Authentication server challenges client.
4. Client responds with proper password or key.
5. Authentication server approves access.
6. Switch grants management access.
Содержание DG-FS4528P
Страница 2: ......
Страница 4: ......
Страница 148: ...CHAPTER 5 Simple Network Management Protocol Configuring SNMPv3 Groups 148 ...
Страница 279: ...CHAPTER 8 Interface Configuration Showing Port or Trunk Statistics 279 Figure 130 Showing Port Statistics ...
Страница 289: ...CHAPTER 10 Address Table Settings Changing the Aging Time 289 4 Click Apply Figure 137 Setting the Address Aging Time ...
Страница 389: ...CHAPTER 17 VoIP Traffic Configuration Configuring Telephony OUI 389 ...
Страница 414: ...CHAPTER 18 Multicast Filtering Multicast VLAN Registration 414 Figure 216 Configuring Static MVR Receiver Group Members ...
Страница 515: ...CHAPTER 22 System Management Commands UPnP 515 TTL 20 Console ...
Страница 972: ......
Страница 973: ...DG FS4528P ...