Chapter 65 AAA
XGS2220 Series User’s Guide
437
65.5 Technical Reference
This section provides technical background information on the topics discussed in this chapter.
65.5.1 Vendor Specific Attribute
RFC 2865 standard specifies a method for sending vendor-specific information between a RADIUS server
and a network access device (for example, the Switch). A company can create Vendor Specific
Attributes (VSAs) to expand the functionality of a RADIUS server.
The Switch supports VSAs that allow you to perform the following actions based on user authentication:
Update
Period
This is the amount of time in minutes before the Switch sends an update to the accounting
server. This is only valid if you select the
start-stop
option for the
Exec
or
Dot1x
entries.
Type
The Switch supports the following types of events to be sent to the accounting servers:
•
System
– Configure the Switch to send information when the following system events occur:
system boots up, system shuts down, system accounting is enabled, system accounting is
disabled.
•
Exec
– Configure the Switch to send information when an administrator logs in and logs out
through the console port, telnet or SSH.
•
Dot1x
– Configure the Switch to send information when an IEEE 802.1x client begins a
session (authenticates through the Switch), ends a session as well as interim updates of a
session.
•
Commands
– Configure the Switch to send information when commands of specified
privilege level and higher are executed on the Switch.
Active
Enable the switch button to activate accounting for a specified event type.
Broadcast
Select this to have the Switch send accounting information to all configured accounting
servers at the same time.
If you do not select this and you have two accounting servers set up, then the Switch sends
information to the first accounting server and if it does not get a response from the accounting
server then it tries the second accounting server.
Mode
The Switch supports two modes of recording login events. Select:
•
start-stop
– to have the Switch send information to the accounting server when a user begins
a session, during a user’s session (if it lasts past the
Update Period
), and when a user ends a
session.
•
stop-only
– to have the Switch send information to the accounting server only when a user
ends a session.
Method
Select whether you want to use
radius
or
for accounting of specific types of events.
is the only method for recording
Commands
type of event.
Privilege
This field is only configurable for
Commands
type of event. Select the threshold command
privilege level for which the Switch should send accounting information. The Switch will send
accounting information when commands at the level you specify and higher are executed on
the Switch.
Apply
Click
Apply
to save your changes to the Switch’s run-time memory. The Switch loses these
changes if it is turned off or loses power, so use the
Save
link on the top navigation panel to
save your changes to the non-volatile memory when you are done configuring.
Cancel
Click
Cancel
to begin configuring this screen afresh.
Table 247 SECURITY > AAA > AAA Setup (continued)
LABEL
DESCRIPTION
Содержание XGS2220 Series
Страница 27: ...27 PART I User s Guide ...
Страница 56: ...56 PART II Technical Reference ...
Страница 154: ...Chapter 20 Cloud Management XGS2220 Series User s Guide 154 Figure 105 SYSTEM Cloud Management ...
Страница 309: ...Chapter 45 Multicast XGS2220 Series User s Guide 309 Figure 226 MVR Group Configuration Example View ...
Страница 467: ...Chapter 68 Policy Rule XGS2220 Series User s Guide 467 Figure 343 Policy Example ...
Страница 555: ...Chapter 78 MAINTENANCE XGS2220 Series User s Guide 555 Figure 413 MAINTENANCE Tech Support Download ...
Страница 562: ...Chapter 79 Networked AV Mode XGS2220 Series User s Guide 562 Figure 418 SYSTEM Cloud Management ...
Страница 616: ...616 PART III Troubleshooting and Appendices ...