Brocade FastIron Ethernet Switch Security Configuration Gu Manual de usuario Pagina 51

  • Descarga
  • Añadir a mis manuales
  • Imprimir
  • Pagina
    / 396
  • Tabla de contenidos
  • MARCADORES
  • Valorado. / 5. Basado en revisión del cliente
Vista de pagina 50
When you configure authentication-method lists for TACACS/TACACS+ authentication, you must create
a separate authentication-method list for Telnet/SSH CLI access, and for access to the Privileged EXEC
level and CONFIG levels of the CLI.
To create an authentication method list that specifies TACACS/TACACS+ as the primary authentication
method for securing Telnet/SSH access to the CLI.
device(config)#enable telnet authentication
device(config)#aaa authentication login default tacacs local
The commands above cause TACACS/TACACS+ to be the primary authentication method for securing
Telnet/SSH access to the CLI. If TACACS/TACACS+ authentication fails due to an error with the server,
authentication is performed using local user accounts instead.
To create an authentication-method list that specifies TACACS/TACACS+ as the primary authentication
method for securing access to Privileged EXEC level and CONFIG levels of the CLI.
device(config)#aaa authentication enable default tacacs local none
The command above causes TACACS/TACACS+ to be the primary authentication method for securing
access to Privileged EXEC level and CONFIG levels of the CLI. If TACACS/TACACS+ authentication
fails due to an error with the server, local authentication is used instead. If local authentication fails, no
authentication is used; the device automatically permits access.
Syntax: [no] aaa authentication { enable | login default } method 1 [ method 2-7 ]
The web-server | enable | login parameter specifies the type of access this authentication-method list
controls. You can configure one authentication-method list for each type of access.
The method1 parameter specifies the primary authentication method. The remaining optional method
parameters specify additional methods to try if an error occurs with the primary method. A method can
be one of the values listed in the Method Parameter column in the following table.
Authentication method values TABLE 3
Method parameter Description
line Authenticate using the password you configured for Telnet access. The Telnet password is
configured using the enable telnet password... command. Refer to Setting a Telnet
password on page 32.
enable Authenticate using the password you configured for the Super User privilege level. This
password is configured using the enable super-user-password... command. Refer to Setting
passwords for management privilege levels on page 32.
local Authenticate using a local user name and password you configured on the device. Local user
names and passwords are configured using the username... command. Refer to Local user
account configuration on page 40.
tacacs Authenticate using the database on a TACACS server. You also must identify the server to
the device using the tacacs-server command.
tacacs+ Authenticate using the database on a TACACS+ server. You also must identify the server to
the device using the tacacs-server command.
radius Authenticate using the database on a RADIUS server. You also must identify the server to the
device using the radius-server command.
Security Access
FastIron Ethernet Switch Security Configuration Guide 51
53-1003088-03
Vista de pagina 50
1 2 ... 46 47 48 49 50 51 52 53 54 55 56 ... 395 396

Comentarios a estos manuales

Sin comentarios