
Lantronix
SM24TBT2DPA and SM24TBT2DPB Web User Guide
2-5.1.3 Authentication Method
This page lets you configure a user with authentication when they log into the switch via one of the
management client interfaces.
SSH
(Secure SHell) is used to securely access the Switch. SSH is a secure
communication protocol that combines authentication and data encryption to provide secure encrypted
communication.
HTTPS
is used to securely access the Switch. HTTPS is a secure communication
protocol that combines authentication and data encryption to provide secure encrypted communication via
the browser. HTTP has no built-in security. Use HTTP redirect if you want all the requests (both HTTP and
HTTPS) to be redirected on HTTPS. Note: the default is HTTPS and HTTP is redirected to HTTPS. Also,
SSH is always enabled, the Telnet default is disabled, and you are given the option to enable Telnet.
Web Interface
To configure Authentication Methods in the web UI:
1. Specify the Client (console, telnet, ssh, http, https) which you want to monitor.
2. Specify the Authentication Method (none, local, radius, ).
3. Check Fallback.
4. Click Apply.
Figure 2-4.1.3: Authentication Method Configuration page
Parameter descriptions:
Client:
The management client for which the configuration below applies (console, telnet, ssh, http, https).
type dropdown
: select no, local, radius, or tacacs. You can also select ‘redirect http to https’.
Methods:
Authentication Method can be set to one of the following values:
no
: authentication is disabled and login is not possible.
redirect
: When HTTPS is enabled, enable HTTP to HTTPS automatic redirect
on the switch.
local
: use the local user database on the switch for authentication.
radius
: use a remote RADIUS server for authentication.
tacacs
: use a remote server for authentication.
Authentication methods that involve remote servers are timed out if the remote servers are offline.
In this case the next method is tried. Each method is tried from left to right and continues until a method
either approves or rejects a user. If a remote server is used for primary authentication it is recommended
to configure secondary authentication as 'local'. This will enable the management client to login via the
local user database if none of the configured authentication servers are alive.
Service
Port
: The TCP port for each client service. A valid port number is 1 ~ 65534. The port numbers
displayed are the commonly-used port numbers for the client types.