
C
HAPTER
14
| Security Measures
AAA Authorization and Accounting
– 268 –
◆
– Filter IP traffic on insecure ports for which the source
address cannot be identified via DHCP snooping.
N
OTE
:
The priority of execution for the filtering commands is Port Security,
Port Authentication, Network Access, Web Authentication, Access Control
Lists, IP Source Guard, and then DHCP Snooping.
AAA A
UTHORIZATION
AND
A
CCOUNTING
The Authentication, authorization, and accounting (AAA) feature provides
the main framework for configuring access control on the switch. The three
security functions can be summarized as follows:
◆
Authentication — Identifies users that request access to the network.
◆
Authorization — Determines if users can access specific services.
◆
Accounting — Provides reports, auditing, and billing for services that
users have accessed on the network.
The AAA functions require the use of configured RADIUS or
servers in the network. The security servers can be defined as sequential
groups that are applied as a method for controlling user access to specified
services. For example, when the switch attempts to authenticate a user, a
request is sent to the first server in the defined group, if there is no
response the second server will be tried, and so on. If at any point a pass
or fail is returned, the process stops.
The switch supports the following AAA features:
◆
Accounting for IEEE 802.1X authenticated users that access the
network through the switch.
◆
Accounting for users that access management interfaces on the switch
through the console and Telnet.
◆
Accounting for commands that users enter at specific CLI privilege
levels.
◆
Authorization of users that access management interfaces on the
switch through the console and Telnet.
To configure AAA on the switch, you need to follow this general process:
1.
Configure RADIUS and server access parameters. See
"Configuring Local/Remote Logon Authentication" on page 269
2.
Define RADIUS and server groups to support the accounting
and authorization of services.
Содержание ES3510MA-DC
Страница 1: ...Management Guide www edge core com 8 Port Layer 2 Fast Ethernet Switch...
Страница 2: ......
Страница 4: ......
Страница 6: ...ABOUT THIS GUIDE 6...
Страница 44: ...FIGURES 44...
Страница 50: ...TABLES 50...
Страница 52: ...SECTION I Getting Started 52...
Страница 62: ...CHAPTER 1 Introduction System Defaults 62...
Страница 80: ...CHAPTER 2 Initial Switch Configuration Managing System Files 80...
Страница 82: ...SECTION II Web Configuration 82...
Страница 98: ...CHAPTER 3 Using the Web Interface Navigating the Web Browser Interface 98...
Страница 126: ...CHAPTER 4 Basic Management Tasks Resetting the System 126...
Страница 164: ...CHAPTER 5 Interface Configuration VLAN Trunking 164 Figure 57 Configuring VLAN Trunking...
Страница 202: ...CHAPTER 7 Address Table Settings Configuring MAC Address Mirroring 202...
Страница 452: ...CHAPTER 17 IP Services Displaying the DNS Cache 452...
Страница 498: ...CHAPTER 19 Using the Command Line Interface CLI Command Groups 498...
Страница 588: ...CHAPTER 22 SNMP Commands 588...
Страница 596: ...CHAPTER 23 Remote Monitoring Commands 596...
Страница 650: ...CHAPTER 24 Authentication Commands Management IP Filter 650...
Страница 738: ...CHAPTER 27 Interface Commands 738...
Страница 760: ...CHAPTER 29 Port Mirroring Commands RSPAN Mirroring Commands 760...
Страница 782: ...CHAPTER 32 Address Table Commands 782...
Страница 810: ...CHAPTER 33 Spanning Tree Commands 810...
Страница 862: ...CHAPTER 35 VLAN Commands Configuring Voice VLANs 862...
Страница 876: ...CHAPTER 36 Class of Service Commands Priority Commands Layer 3 and 4 876...
Страница 932: ...CHAPTER 38 Multicast Filtering Commands Multicast VLAN Registration 932...
Страница 956: ...CHAPTER 39 LLDP Commands 956...
Страница 1020: ...CHAPTER 42 Domain Name Service Commands 1020...
Страница 1026: ...CHAPTER 43 DHCP Commands DHCP Client 1026...
Страница 1058: ...CHAPTER 44 IP Interface Commands IPv6 Interface 1058...
Страница 1060: ...SECTION IV Appendices 1060...
Страница 1065: ...APPENDIX A Software Specifications Management Information Bases 1065 Trap RFC 1215 UDP MIB RFC 2013...
Страница 1066: ...APPENDIX A Software Specifications Management Information Bases 1066...
Страница 1088: ...COMMAND LIST 1088...
Страница 1097: ......
Страница 1098: ...ES3510MA DC E122010 ST R01 150200000251A...