© Copyright Lenovo 2017
Chapter 5: Authentication & Authorization Protocols
103
RADIUS Attributes for Enterprise NOS User Privileges
When
the
user
logs
in,
the
switch
authenticates
his/her
level
of
access
by
sending
the
RADIUS
access
request,
that
is,
the
client
authentication
request,
to
the
RADIUS
authentication
server.
If
the
remote
user
is
successfully
authenticated
by
the
authentication
server,
the
switch
will
verify
the
privileges
of
the
remote
user
and
authorize
the
appropriate
access.
The
administrator
has
two
options:
to
allow
backdoor
access
via
Telnet,
SSH,
HTTP,
or
HTTPS;
to
allow
secure
backdoor
access
via
console,
Telnet,
SSH,
or
BBI.
Secure
backdoor
provides
access
to
the
switch
when
the
RADIUS
servers
cannot
be
reached.
The
default
CN4093
setting
for
backdoor
and
secure
backdoor
access
is
disabled
.
Backdoor
access
is
always
enabled
on
the
console
port.
Irrespective
of
backdoor
being
enabled
or
not,
you
can
always
access
the
switch
via
the
console
port
by
using
noradius
as
radius
username.
You
can
then
enter
the
username
and
password
configured
on
the
switch.
If
you
are
trying
to
connect
via
SSH/Telnet/HTTP/HTTPS,
there
are
two
possibilities:
Backdoor
is
enabled:
The
switch
acts
like
it
is
connecting
via
console.
Secure
backdoor
is
enabled:
You
must
enter
the
username:
noradius
.
The
switch
checks
if
RADIUS
server
is
reachable.
If
it
is
reachable,
then
you
must
authenticate
via
remote
authentication
server.
Only
if
RADIUS
server
is
not
reachable,
you
will
be
prompted
for
local
user/password
to
be
authenticated
against
these
local
credentials.
All
user
privileges,
other
than
those
assigned
to
the
Administrator,
have
to
be
defined
in
the
RADIUS
dictionary.
RADIUS
attribute
6
which
is
built
into
all
RADIUS
servers
defines
the
administrator.
The
file
name
of
the
dictionary
is
RADIUS
vendor
‐
dependent.
The
following
RADIUS
attributes
are
defined
for
Enterprise
NOS
user
privileges
levels:
Table 8.
Enterprise
NOS
‐
proprietary
Attributes
for
RADIUS
User Name/Access
User-Service-Type
Value
User
Vendor
‐
supplied
255
Operator
Vendor
‐
supplied
252
Administrator
(
USERID
)
Vendor
‐
supplied
6
Содержание Flex System Fabric CN4093
Страница 27: ... Copyright Lenovo 2017 27 Part 1 Getting Started ...
Страница 28: ...28 CN4093 Application Guide for N OS 8 4 ...
Страница 58: ...58 CN4093 Application Guide for N OS 8 4 ...
Страница 72: ...72 CN4093 Application Guide for N OS 8 4 ...
Страница 85: ... Copyright Lenovo 2017 85 Part 2 Securing the Switch ...
Страница 86: ...86 CN4093 Application Guide for N OS 8 4 ...
Страница 98: ...98 CN4093 Application Guide for N OS 8 4 ...
Страница 112: ...112 CN4093 Application Guide for N OS 8 4 ...
Страница 136: ...136 CN4093 Application Guide for N OS 8 4 ...
Страница 156: ...156 CN4093 Application Guide for N OS 8 4 ...
Страница 192: ...192 CN4093 Application Guide for N OS 8 4 ...
Страница 228: ...228 CN4093 Application Guide for N OS 8 4 ...
Страница 229: ... Copyright Lenovo 2017 229 Part 4 Advanced Switching Features ...
Страница 230: ...230 CN4093 Application Guide for N OS 8 4 ...
Страница 298: ...298 CN4093 Application Guide for N OS 8 4 ...
Страница 382: ...382 CN4093 Application Guide for N OS 8 4 ...
Страница 392: ...392 CN4093 Application Guide for N OS 8 4 ...
Страница 416: ...416 CN4093 Application Guide for N OS 8 4 ...
Страница 452: ...452 CN4093 Application Guide for N OS 8 4 ...
Страница 466: ...466 CN4093 Application Guide for N OS 8 4 ...
Страница 496: ...496 CN4093 Application Guide for N OS 8 4 ...
Страница 508: ...508 CN4093 Application Guide for N OS 8 4 ...
Страница 510: ...510 CN4093 Application Guide for N OS 8 4 ...
Страница 514: ...514 CN4093 Application Guide for N OS 8 4 ...
Страница 538: ...538 CN4093 Application Guide for N OS 8 4 ...
Страница 539: ... Copyright Lenovo 2017 539 Part 7 Network Management ...
Страница 540: ...540 CN4093 Application Guide for N OS 8 4 ...
Страница 554: ...554 CN4093 Application Guide for N OS 8 4 ...
Страница 576: ...576 CN4093 Application Guide for N OS 8 4 ...
Страница 596: ...596 CN4093 Application Guide for N OS 8 4 ...
Страница 604: ...604 CN4093 Application Guide for N OS 8 4 ...
Страница 609: ... Copyright Lenovo 2017 609 Part 9 Appendices ...
Страница 610: ...610 CN4093 Application Guide for N OS 8 4 ...
Страница 626: ...626 CN4093 Application Guide for N OS 8 4 ...
Страница 633: ......
Страница 634: ...Part Number 00MY375 Printed in USA IP P N 00MY375 ...