SROS Command Line Interface Reference Guide
Global Configuration Mode Command Set
5991-2114
© Copyright 2007 Hewlett-Packard Development Company, L.P.
321
aaa on
Use the
aaa on
command to activate the AAA subsystem. Use the
no
form of this command to deactivate
AAA.
Syntax Description
No subcommands.
Default Values
By default, AAA is not activated.
Functional Notes
By default, the AAA subsystem is turned off and authentication follows the line technique (local, line, etc.).
Once activated, the AAA lists override the methods specified in the line command.
Technology Review
AAA stands for authentication, authorization, and accounting. The SROS AAA subsystem currently supports
authentication. Authentication is the means by which a user is granted access to the device (router). For
instance, a username/password is authenticated before the user can use the CLI. VPN clients can also verify
username/password before getting access through the device.
There are several methods that can be used to authenticate a user:
NONE
Instant access
LINE-PASSWORD
Use the line password (telnet 0-4 or console 0-1)
ENABLE-PASSWORD
Use the enable password
LOCAL-USERS
Use the local user database
GROUP
<groupname>
Use a group of remote RADIUS or servers
The AAA system allows the user to create a named list of these methods to try in order (in case one fails, it falls
to the next one). This named list is then attached to a portal (telnet 0-4 or console 0-1). When a user telnets in or
accesses the terminal, the AAA system uses the methods from the named list to authenticate the user.
The AAA system must be turned on to be active. By default it is off. Use the
aaa on
command to activate the
AAA system.
If a portal is not explicitly assigned a named list, the name
default
is automatically assigned to it. The user can
customize the
default
list just like any other list. If no
default
list is configured, the following default behavior
applies (defaults are based on portal):
•
Instant access (NONE) is assigned to the CONSOLE using the
default
list (when the list has not been
configured).
•
The local user database is used for TELNETS using the
default
list (when the list has not been
configured).
•
No access is granted for FTP access using the
default
list (when the list has not been configured).
Содержание ProCurve Secure 7102dl
Страница 2: ......
Страница 3: ...SROS Command Line Interface Reference Guide Software Version J 08 03 September 2007 61195880L1 35H ...
Страница 1454: ......