Chapter 9:
Authentication
192
Console Server & RIM Gateway User Manual
AUTHENTICATION
The
console server
platform is a dedicated Linux computer, and it embodies a myriad of popular and proven Linux
software modules for networking, secure access (OpenSSH) and communications (OpenSSL) and sophisticated user
authentication (PAM, RADIUS, , Kerberos and LDAP).
This chapter details how the
Administrator
can use the Management Console to establish remote AAA
authentication for all connections to the
console server
and attached serial and network host devices
This chapter also covers establishing a secure link to the Management Console using HTTPS and using
OpenSSL and OpenSSH for establishing secure Administration connection to the
console server
More details on RSA SecurID and working with Windows IAS can be found on the online FAQs.
9.1
Authentication Configuration
Authentication can be performed locally, or remotely using an LDAP, Radius, Kerberos or authentication
server.
The default authentication method for the
console server
is Local.
Any authentication method that is configured will be used for authentication of any user who attempts to log in through
Telnet, SSH or the Web Manager to the
console server
and any connected serial port or network host devices.
The
console server
can be configured to the default (
Local
) or an alternate authentication method (
TACACS
,
RADIUS
,
LDAP
or
Kerberos
) with the option of a selected order in which local and remote authentication is to be used:
Local
TACACS /RADIUS/LDAP/Kerberos
: Tries local authentication first, falling back to remote if local fails
TACACS /RADIUS/LDAP/Kerberos
Local
: Tries remote authentication first, falling back to local if remote fails
TACACS /RADIUS/LDAP/Kerberos
Down Local
: Tries remote authentication first, falling back to local if the
remote authentication returns an error condition (e.g. the remote authentication server is down or inaccessible)
9.1.1
Local authentication
Select
Serial and Network: Authentication
and check
Local
Click
Apply
9.1.2
TACACS authentication
Perform the following procedure to configure the authentication method to be used whenever the
console
server
or any of its serial ports or hosts is accessed:
Содержание ACM5000
Страница 3: ......
Страница 10: ...Table of Contents 10 Console Server RIM Gateway User Manual...
Страница 11: ......
Страница 94: ...Chapter 5 Firewall Failover and Out of Band 94 Console Server RIM Gateway User Manual...
Страница 119: ......
Страница 149: ......
Страница 191: ......
Страница 205: ......
Страница 225: ......
Страница 303: ......
Страница 313: ......
Страница 323: ......