6-39
RADIUS Authentication, Authorization, and Accounting
Commands Authorization
The results of using the HP-Command-String and HP-Command-Exception
attributes in various combinations are shown below.
You must configure the RADIUS server to provide support for the HP VSAs.
There are multiple RADIUS server applications; the two examples below show
how a dictionary file can be created to define the VSAs for that RADIUS server
application.
HP-Command-String HP-Command-Exception
Description
Not present
Not present
If command authorization is enabled
and the RADIUS server does not
provide any authorization attributes in
an Access-Accept packet, the user is
denied access to the server. This
message appears: “Access denied: no
user’s authorization info supplied by
the RADIUS server.”
Not present
DenyList-PermitOthers(1)
Authenticated user is allowed to
execute all commands available on
the switch.
Not present
PermitList-DenyOthers(0)
Authenticated user can only execute
a minimal set of commands (those that
are available by default to any user).
Commands List
DenyList-PermitOthers(1)
Authenticated user may execute all
commands except those in the
Commands list.
Commands List
PermitList-DenyOthers(0)
Authenticated user can execute only
those commands provided in the
Commands List, plus the default
commands.
Commands List
Not present
Authenticated user can only execute
commands from the Commands List,
plus the default commands.
Empty Commands
List
Not present
Authenticate user can only execute a
minimal set of commands (those that
are available by default to any user).
Empty Commands
List
DenyList-PermitOthers(1)
Authenticated user is allowed to
execute all commands available on
the switch.
Empty Commands
List
PermitList-DenyOthers(0)
Authenticate user can only execute a
minimal set of commands (those that
are available by default to any user).
Содержание E3800 Series
Страница 1: ...HP Switch Software E3800 switches Software version KA 15 03 September 2011 Access Security Guide ...
Страница 2: ......
Страница 3: ...HP Networking E3800 Switches Access Security Guide September 2011 KA 15 03 ...
Страница 30: ...xxviii ...
Страница 86: ...2 36 Configuring Username and Password Security Password Recovery ...
Страница 186: ...4 72 Web and MAC Authentication Client Status ...
Страница 290: ...6 74 RADIUS Authentication Authorization and Accounting Dynamic Removal of Authentication Limits ...
Страница 364: ...8 32 Configuring Secure Shell SSH Messages Related to SSH Operation ...
Страница 510: ...10 130 IPv4 Access Control Lists ACLs General ACL Operating Notes ...
Страница 548: ...11 38 Configuring Advanced Threat Protection Using the Instrumentation Monitor ...
Страница 572: ...12 24 Traffic Security Filters and Monitors Configuring Traffic Security Filters ...
Страница 659: ...14 11 Configuring and Monitoring Port Security Port Security Figure 14 5 Examples of Show Mac Address Outputs ...
Страница 730: ...20 Index ...
Страница 731: ......