Configuration Guide
AAA Configuration
Configure the security protocol parameters if you decide to use the security server, such
as RADIUS. See Configuring Radius for details.
Define the authentication method list by using the
aaa authentication
command.
Applying method list on a specific interface or line, if possible.
Caution
is not supported by the DOT1X authentication.
Configuring the AAA Login Authentication
This section deals with how to configure the AAA Login authentication methods supported by
our product:
Caution
Only after the AAA is enabled through the command
aaa new-model
in the
global configuration mode, the AAA security features are available for your
configuration. For the details, see
AAA Overview
.
In many cases, the user needs to Telnet the network access server (NAS). Once such a
connection is set up, it is possible to configure NAS remotely. To prevent unauthorized
accesses to the network, it is required to perform authentication on the user identity.
The AAA security services make it easy for the network devices to perform line-based
authentication. No matter which line authentication method you decide to use, you just need to
execute the
aaa authentication login
command to define one or more authentication method
list and apply it on the specific line that need the line authentication.
To configure the AAA PPP authentication, execute the following command in the global
configuration mode:
Command
Function
configure terminal
Enter the global configuration mode.
aaa new-model
Enable AAA.
aaa authentication login
{
default
|list-name} method1 [method2...]
Define an accounting method list, or repeat this
command to define more.
line vty
line-num
Enter the line that needs to apply the AAA
authentication.
login authentication
{
default
|
list-name
}
Apply the method list on the line.
The keyword "list-name" is used to name the created authentication method list, which can be
any string. The keyword "method" means the actual algorithm for authentication. Only when
the current method returns ERROR (no reply), the next authentication method will be
attempted. If the current method returns FAIL, no authentication method will be used any more.
To make the authentication return successfully, even if no specified methods reply, it is
possible to specific "none" as the last authentication method.
Содержание RG-S2900G-E Series
Страница 1: ...RG S2900G E Series Switch RGOS Configuration Guide Release 10 4 2b12 p1 ...
Страница 91: ...Configuration Guide Configuring PoE Configuration ...
Страница 133: ...Configuration Guide EEE Configuration ...
Страница 319: ...Configuration Guide QinQ Configuration ...
Страница 408: ......
Страница 409: ...IP Routing Configuration 1 Static Route Configuration ...
Страница 412: ......
Страница 413: ...Multicast Configuration 1 IGMP Snooping Configuration 2 MLD Snooping Configuration ...
Страница 621: ...Configuration Guide CPU Protection Configuration udp helper 180 4 dhcp client 180 4 lacp 180 4 ...
Страница 757: ......
Страница 758: ...ACL QoS Configuration 1 Access Control List Configuration 2 QoS Configuration ...
Страница 801: ...Reliability Configuration 1 RLDP Configuration 2 TPP Configuration 3 SEM Configuration ...
Страница 901: ...Configuration Guide ERSPAN Configuration ...
Страница 902: ...Web based Configuration 1 Web based Configuration ...