Chapter 6 Configuring authentication
241
Nortel Secure Network Access Switch 4050 User Guide
Configuring advanced settings using the CLI
You can configure the Nortel SNAS 4050 domain to use one method for
authentication and another for authorization.
For example, there are three authentication methods configured for the domain:
Local (auth ID 1), RADIUS (auth ID 2), and LDAP (auth ID 3). The user groups
are stored in an LDAP database. You can configure the domain to have the Local
and LDAP methods used for authorization after users have been authenticated by
RADIUS. In this example, the command is:
/cfg/domain 1/aaa/auth 2/
adv/groupauth 1,3
. When a user logs on through RADIUS, the system first
checks the RADIUS database. If no match is found, the system checks the other
authentication schemes (in the order in which you listed them in the
groupauth
command) to see if the user name can be matched against user groups defined in
the authentication databases. The first group matched is returned to the Nortel
SNAS 4050 as the user’s group, and determines the user’s access privileges for the
session.
radius|ldap|local
Accesses a method-specific menu, in order to
configure settings for the method. The option displayed
depends on the method type.
•
radius
— accesses the
RADIUS
menu (see
“Configuring RADIUS authentication using the CLI”
on page 242
)
•
ldap
— accesses the
LDAP
menu (see
“Configuring LDAP authentication using the CLI” on
page 249
)
•
local
— accesses the
Local database menu
(see
“Configuring local database authentication
using the CLI” on page 261
)
adv
Accesses the
Advanced
menu, in order to configure
the current method to retrieve group information from
other authentication schemes (see
“Configuring
advanced settings using the CLI” on page 241
).
del
Removes the method from the Nortel SNAS 4050
domain.
/cfg/domain 1/aaa/auth <
auth ID
>
followed by:
Содержание 4050
Страница 24: ...24 Contents 320818 A ...
Страница 48: ...48 Chapter 1 Overview 320818 A ...
Страница 70: ...70 Chapter 2 Initial setup 320818 A ...
Страница 190: ...190 Chapter 4 Configuring the domain 320818 A ...
Страница 232: ...232 Chapter 5 Configuring groups and profiles 320818 A ...
Страница 352: ...352 Chapter 7 TunnelGuard SRS Builder 320818 A ...
Страница 456: ...456 Chapter 9 Customizing the portal and user logon 320818 A ...
Страница 568: ...568 Chapter 10 Configuring system settings 320818 A ...
Страница 722: ...722 Chapter 13 Viewing system information and performance statistics 320818 A ...
Страница 756: ...756 Chapter 14 Maintaining and managing the system 320818 A ...
Страница 768: ...768 Chapter 15 Upgrading or reinstalling the software 320818 A ...
Страница 802: ...802 Chapter 17 Configuration example 320818 A ...
Страница 880: ...880 Appendix C Supported MIBs 320818 A ...
Страница 900: ...900 Appendix F Configuring DHCP to auto configure IP Phones 320818 A ...