User Authentication
3-61
3
AAA Authorization and Accounting
The Authentication, authorization, and accounting (AAA) feature provides the main
framework for configuring access control on the switch. The three security functions
can be summarized as follows:
• Authentication — Identifies users that request access to the network.
• Authorization — Determines if users can access specific services.
• Accounting — Provides reports, auditing, and billing for services that users have
accessed on the network.
The AAA functions require the use of configured RADIUS or servers in
the network. The security servers can be defined as sequential groups that are then
applied as a method for controlling user access to specified services. For example,
when the switch attempts to authenticate a user, a request is sent to the first server
in the defined group, if there is no response the second server will be tried, and so
on. If at any point a pass or fail is returned, the process stops.
The switch supports the following AAA features:
• Accounting for IEEE 802.1X authenticated users that access the network through
the switch.
• Accounting for users that access management interfaces on the switch through the
console and Telnet.
• Accounting for commands that users enter at specific CLI privilege levels.
• Authorization of users that access management interfaces on the switch through
the console and Telnet.
To configure AAA on the switch, you need to follow this general process:
1. Configure RADIUS and server access parameters. See "Configuring
Local/Remote Logon Authentication" on page 3-56.
2. Define RADIUS and server groups to support the accounting and
authorization of services.
3. Define a method name for each service to which you want to apply accounting or
authorization and specify the RADIUS or server groups to use.
4. Apply the method names to port or line interfaces.
Note:
This guide assumes that RADIUS and servers have already been
configured to support AAA. The configuration of RADIUS and server
software is beyond the scope of this guide, refer to the documentation provided
with the RADIUS or server software.
Содержание 8126PL2-F
Страница 1: ...MANAGEMENT GUIDE ta TigerSwitchTM 10 100 1000 L2 Lite SMB PoE Gigabit Switch SMC8126PL2 F ...
Страница 2: ......
Страница 6: ...vi ...
Страница 22: ...Contents xxii ...
Страница 26: ...Tables xxvi ...
Страница 48: ...Initial Configuration 2 10 2 ...
Страница 117: ...User Authentication 3 69 3 Web Click Security AAA Summary Figure 3 43 AAA Accounting Summary ...
Страница 590: ...Command Line Interface 4 302 4 ...
Страница 604: ...Glossary Glossary 8 ...
Страница 612: ...Index 8 Index ...
Страница 613: ......
Страница 614: ...149100000023A R01 SMC8126PL2 F ...