9-21
Using Passwords and To Protect Against Unauthorized Access
Authentication for Central Control of Switch Access Security
Usi
n
g P
a
sswor
ds and
TA
C
A
CS+
Name
Default
Range
host <
ip-addr
> [key <
key-string
>
none
n/a
Specifies the IP address of a device running a server application. Optionally, can also specify the unique, per-
server encryption key to use when each assigned server has its own, unique key. For more on the encryption key, see
“Using the Encryption Key” on page 26 and the documentation provided with your server application.
You can enter up to three IP addresses; one first-choice and two (optional) backups (one second-choice and one third-
choice).
Use
show tacacs
to view the current IP address list.
If the first-choice server fails to respond to a request, the switch tries the second address, if any, in the show
tacacs list. If the second address also fails, then the switch tries the third address, if any.
(See figure 9-6, "Example of the Switch’s Configuration Listing" on page 15.)
The priority (first-choice, second-choice, and third-choice) of a server in the switch’s configuration
depends on the order in which you enter the server IP addresses:
1.When there are no servers configured, entering a server IP address makes that server the first-choice
server.
2.When there is one serves already configured, entering another server IP address makes that server the
second-choice (backup) server.
3.When there are two servers already configured, entering another server IP address makes that server
the third-choice (backup) server.
• The above position assignments are fixed. Thus, if you remove one server and replace it with another, the new server
assumes the priority position that the removed server had. For example, suppose you configured three servers, A, B,
and C, configured in order:
First-Choice:
A
Second-Choice:
B
Third-Choice: C
• If you removed server B and then entered server X, the server order of priority would be:
First-Choice:
A
Second-Choice:
X
Third-Choice: C
• If there are two or more vacant slots in the server priority list and you enter a new IP address, the new
address will take the vacant slot with the highest priority. Thus, if A, B, and C are configured as above and you (1)
remove A and B, and (2) enter X and Y (in that order), then the new server priority list would be X, Y, and C.
• The easiest way to change the order of the servers in the priority list is to remove all server addresses in
the list and then re-enter them in order, with the new first-choice server address first, and so on.
To add a new address to the list when there are already three addresses present, you must first remove one of the
currently listed addresses.
See also “General Authentication Process Using a Server” on page 24.
Name
Default
Range
key <
key-string
>
none (null) n/a
Specifies the optional, global "encryption key" that is also assigned in the server(s) that the switch will access
for authentication. This option is subordinate to any "per-server" encryption keys you assign, and applies only to accessing
servers for which you have not given the switch a "per-server" key. (See the
host <
ip-addr
> [key <
key-string
>
entry at the beginning of this table.)
For more on the encryption key, see “Using the Encryption Key” on page 26 and the documentation provided with your
server application.
Содержание ProCurve 4108gl Bundle
Страница 1: ...hp procurve switch 4108gl management and configuration guide www hp com go hpprocurve ...
Страница 2: ......
Страница 3: ...HP Procurve Switch 4108GL Management and Configuration Guide Software Release G 01 xx or Later ...
Страница 40: ...2 16 Using the Menu Interface Where To Go From Here Using the Menu Interface ...
Страница 82: ...4 26 Using the HP Web Browser Interface Status Reporting Features Using the HP Web Browser Interface ...
Страница 116: ...6 14 Interface Access and System Information System Information Interface Access and System Information ...
Страница 154: ...8 24 Time Protocols SNTP Messages in the Event Log Time Protocols ...
Страница 230: ...11 32 Optimizing Port Usage Through Traffic Control and Port Trunking Port Trunking Ports Traffic Control and Trunking ...
Страница 350: ...14 44 Port Based Virtual LANs VLANs and GVRP GVRP Port Based Virtual LANs VLANs and GVRP ...
Страница 383: ...16 13 Spanning Tree Protocol STP How STP Operates Spanning Tree Protocol STP ...
Страница 384: ...16 14 Spanning Tree Protocol STP How STP Operates Spanning Tree Protocol STP ...
Страница 442: ...18 30 Troubleshooting Restoring a Flash Image Troubleshooting ...
Страница 466: ...B 6 MAC Address Management Determining MAC Addresses MAC Address Management ...
Страница 470: ......
Страница 481: ...Index 11 Index write memory effect on menu interface 2 13 X Xmodem OS download A 6 ...
Страница 482: ......