5-19
RADIUS Authentication, Authorization and Accounting
Commands Authorization
Displaying Authorization Information
You can show the authorization information by entering this command:
An example of the output is shown.
Figure 5-7. Example of Show Authorization Command
Configuring Commands Authorization on a RADIUS
Server
Using Vendor Specific Attributes (VSAs)
Some RADIUS-based features implemented on ProCurve switches use HP
VSAs for information exchange with the RADIUS server. RADIUS Access-
Accept packets sent to the switch may contain the vendor-specific informa-
tion. The attributes supported with
commands
authorization are:
■
HP-Command-String: List of commands (regular expressions) that
are permitted (or denied) execution by the user. The commands are
delimited by semi-colons and must be between 1 and 249 characters
in length. Multiple instances of this attribute may be present in
Access-Accept packets. (A single instance may be present in
Accounting-Request packets.)
■
HP-Command-Exception: A flag that specifies whether the
commands indicated by the HP-Command-String attribute are
permitted or denied to the user. A zero (0) means permit all listed
commands and deny all others; a one (1) means deny all listed
commands and permit all others.
Syntax:
show authorization
Configures authorization for controlling access to CLI
commands. When enabled, the switch checks the list of commands
supplied by the RADIUS server during user authentication to
determine if a command entered by the user can be executed.
ProCurve(config)# show authorization
Status and Counters - Authorization Information
Type | Method
-------- + ------
Commands | RADIUS
Содержание ProCurve 2510G Series
Страница 1: ...Access Security Guide www procurve com ProCurve Series 2510G Switches Y 11 XX ...
Страница 2: ......
Страница 3: ...ProCurve Series 2510G Switches Access Security Guide June 2008 ...
Страница 12: ...x ...
Страница 26: ...1 10 Getting Started Need Only a Quick Start ...
Страница 105: ...4 31 TACACS Authentication Configuring TACACS on the Switch ...
Страница 106: ...4 32 TACACS Authentication Configuring TACACS on the Switch ...
Страница 176: ...6 30 Configuring Secure Shell SSH Messages Related to SSH Operation ...
Страница 198: ...7 22 Configuring Secure Socket Layer SSL Common Errors in SSL Setup ...
Страница 296: ...9 40 Configuring and Monitoring Port Security Configuring Protected Ports ...
Страница 310: ...10 14 Using Authorized IP Managers Operating Notes ...
Страница 318: ...8 Index ...
Страница 319: ......