Authentication
Configuring on the Switch
Authentication Parameters
Table 4-1. AAA Authentication Parameters Parameters
Name
Default
Range
Function
console, Telnet,
n/a
n/a
Specifies the access method used when authenticating.
SSH, web or port-
access
authentication only uses the console, Telnet or SSH access methods.
enable
n/a
n/a
Specifies the Manager (read/write) privilege level for the access
method being configured.
login <privilege
mode>
privilege-mode
disabled
n/a
login:
Specifies the Operator (read-only) privilege level for the
access method being configured.
The
privilege-mode
option enables for a single login. The
authorized privilege level (Operator or Manager) is returned to the
switch by the server.
local
- or
tacacs
local
n/a
Specifies the primary method of authentication for the access
method being configured.
local:
Use the username/password pair configured locally in the
switch for
the privilege level being configured
tacacs:
Use a server.
local
none
n/a
Specifies the secondary (backup) type of authentication being
- or -
configured.
none
local:
The username/password pair configured locally in the switch
for the
privilege level being configured
none:
No secondary type of authentication for the specified
method/privilege path.
(Available only if the primary method of
authentication for the access being configured is local.)
Note:
If you do not specify this parameter in the command line, the
switch automatically assigns the secondary method as follows:
• If the primary method is
tacacs
, the
only
secondary method is
local
.
• If the primary method is
local
, the default secondary method is
none
.
num-attempts
3
1 - 10
In a given session, specifies how many tries at entering the correct
username/password pair are allowed before access is denied and
the session terminated.
Configuring the Server for Single Login
In order for the single login feature to work correctly, you need to check some
entries in the User Setup on the server.
In the User Setup, scroll to the Advanced Settings section. Make
sure the radio button for “Max Privilege for any AAA Client” is checked and
the level is set to 15, as shown in Figure 4-4. Privileges are represented by the
4-13
Содержание PROCURVE 2910AL
Страница 1: ...Access Security Guide ProCurve Switches W 14 03 2910al www procurve com ...
Страница 2: ......
Страница 3: ...HP ProCurve 2910al Switch February 2009 W 14 03 Access Security Guide ...
Страница 84: ...Configuring Username and Password Security Front Panel Security 2 36 ...
Страница 156: ...TACACS Authentication Operating Notes 4 30 ...
Страница 288: ...Configuring Secure Socket Layer SSL Common Errors in SSL setup 8 22 ...
Страница 416: ...Configuring Advanced Threat Protection Using the Instrumentation Monitor 10 28 ...
Страница 516: ...Configuring Port Based and User Based Access Control 802 1X Messages Related to 802 1X Operation 12 76 ...
Страница 527: ...Configuring and Monitoring Port Security Port Security Figure 13 4 Examples of Show Mac Address Outputs 13 11 ...
Страница 572: ...Using Authorized IP Managers Operating Notes 14 14 ...
Страница 592: ...12 Index ...
Страница 593: ......
Страница 594: ... Copyright 2009 Hewlett Packard Development Company L P February 2009 Manual Part Number 5992 5439 ...