6-12
RADIUS Authentication, Authorization, and Accounting
Configuring the Switch for RADIUS Authentication
Figure 6-3. Example Configuration for RADIUS Authentication
N o t e
If you configure the Login Primary method as
local
instead of
radius
(and local
passwords are configured on the switch), then clients connected to your
network can gain access to either the Operator or Manager level without
encountering the RADIUS authentication specified for Enable Primary. Refer
to “Local Authentication Process” on page 6-34.
2. Enable the (Optional) Access Privilege Option
In the default RADIUS operation, the switch automatically admits any authen-
ticated client to the Login (Operator) privilege level, even if the RADIUS server
specifies Enable (Manager) access for that client. Thus, an authenticated user
authorized for the Manager privilege level must authenticate again to change
privilege levels. Using the optional
login privilege-mode
command overrides
HP Switch(config)# aaa authentication telnet login radius none
HP Switch(config)# aaa authentication telnet enable radius none
HP Switch(config)# aaa authentication ssh login radius none
HP Switch(config)# aaa authentication ssh enable radius none
HP Switch(config)# show authentication
Status and Counters - Authentication Information
Login Attempts : 3
Respect Privilege : Disabled
| Login Login Login
Access Task | Primary Server Group Secondary
----------- + ---------- ------------ ----------
Console | Local None
Telnet | Radius None
Port-Access | Local None
Webui | Local None
SSH | Radius None
Web-Auth | ChapRadius radius None
MAC-Auth | ChapRadius radius None
| Enable Enable Enable
Access Task | Primary Server Group Secondary
----------- + ---------- ------------ ----------
Console | Local None
Telnet | Radius None
Webui | Local None
SSH | Radius None
The switch now
allows Telnet and
SSH authentication
only through
RADIUS.
Содержание E3800 Series
Страница 1: ...HP Switch Software E3800 switches Software version KA 15 03 September 2011 Access Security Guide ...
Страница 2: ......
Страница 3: ...HP Networking E3800 Switches Access Security Guide September 2011 KA 15 03 ...
Страница 30: ...xxviii ...
Страница 86: ...2 36 Configuring Username and Password Security Password Recovery ...
Страница 186: ...4 72 Web and MAC Authentication Client Status ...
Страница 290: ...6 74 RADIUS Authentication Authorization and Accounting Dynamic Removal of Authentication Limits ...
Страница 364: ...8 32 Configuring Secure Shell SSH Messages Related to SSH Operation ...
Страница 510: ...10 130 IPv4 Access Control Lists ACLs General ACL Operating Notes ...
Страница 548: ...11 38 Configuring Advanced Threat Protection Using the Instrumentation Monitor ...
Страница 572: ...12 24 Traffic Security Filters and Monitors Configuring Traffic Security Filters ...
Страница 659: ...14 11 Configuring and Monitoring Port Security Port Security Figure 14 5 Examples of Show Mac Address Outputs ...
Страница 730: ...20 Index ...
Страница 731: ......