Authentication
Terminology Used in TACACS Applications:
server for authentication services. If the switch fails to connect to
any server, it defaults to its own locally assigned passwords for
authentication control if it has been configured to do so. For both Console
and Telnet access you can configure a login (read-only) and an enable (read/
write) privilege level access.
does not affect web browser interface access. See “Controlling Web
Browser Interface Access” on page 4-27.
Terminology Used in TACACS
Applications:
■
NAS (Network Access Server):
This is an industry term for a TACACS-
aware device that communicates with a TACACS server for authentication
services. Some other terms you may see in literature describing TACACS
operation are
communication server
,
remote access server
, or
terminal
server
. These terms apply to a switch when is enabled on the
switch (that is, when the switch is TACACS-aware).
■
Server:
The server or management station configured as an
access control server for TACACS-enabled devices. To use with
a switch covered in this guide and any other TACACS-capable devices in
your network, you must purchase, install, and configure a
server application on a networked server or management station in the
network. The server application you install will provide various
options for access control and access notifications. For more on the
services available to you, see the documentation provided with
the server application you will use.
■
Authentication:
The process for granting user access to a device through
entry of a user name and password and comparison of this username/
password pair with previously stored username/password data. Authen
tication also grants levels of access, depending on the privileges assigned
to a user name and password pair by a system administrator.
•
Local Authentication:
This method uses username/password
pairs configured locally on the switch; one pair each for manager-
level and operator-level access to the switch. You can assign local
usernames and passwords through the CLI or web browser inter
face. (Using the menu interface you can assign a local password,
but not a username.) Because this method assigns passwords to
the switch instead of to individuals who access the switch, you
must distribute the password information on each switch to
4-3
Содержание PROCURVE 2910AL
Страница 1: ...Access Security Guide ProCurve Switches W 14 03 2910al www procurve com ...
Страница 2: ......
Страница 3: ...HP ProCurve 2910al Switch February 2009 W 14 03 Access Security Guide ...
Страница 84: ...Configuring Username and Password Security Front Panel Security 2 36 ...
Страница 156: ...TACACS Authentication Operating Notes 4 30 ...
Страница 288: ...Configuring Secure Socket Layer SSL Common Errors in SSL setup 8 22 ...
Страница 416: ...Configuring Advanced Threat Protection Using the Instrumentation Monitor 10 28 ...
Страница 516: ...Configuring Port Based and User Based Access Control 802 1X Messages Related to 802 1X Operation 12 76 ...
Страница 527: ...Configuring and Monitoring Port Security Port Security Figure 13 4 Examples of Show Mac Address Outputs 13 11 ...
Страница 572: ...Using Authorized IP Managers Operating Notes 14 14 ...
Страница 592: ...12 Index ...
Страница 593: ......
Страница 594: ... Copyright 2009 Hewlett Packard Development Company L P February 2009 Manual Part Number 5992 5439 ...