User`s guide
143
create authen_login method_list_name
Purpose To create a user-defined list of authentication methods for users
logging on to the Switch.
Syntax
create authen_login method_list_name <string 12>
Description The create authen_login method_list_name command creates a
list of authentication techniques for user login. The Switch can
support up to eight method lists, but one is reserved as a default and
cannot be deleted. Multiple method lists must be created and
configured separately.
Parameters <string 12> - Defines the method_list_name to be created as a string
of up to 12 alphanumeric characters.
Restrictions Only administrator-level users can issue this command.
Example usage:
To create the method list “Trinity”:
DGS3100# create authen_login method_list_name Trinity
Success.
DGS3100#
config authen_login
Purpose To configure a user-defined or default method list of authentication
methods for user login.
Syntax
config authen_login [default | method_list_name <string 12>]
method {tacacs+ | radius | local | none}
Description The config authen_login command configures a user-defined or
default method list of authentication methods for users logging on to
the Switch. The sequence of methods implemented in this command
will affect the authentication result. For example, if a user enters a
sequence of methods like tacacs – xtacacs – local, the Switch will
send an authentication request to the first tacacs host in the server
group. If no response comes from the server host, the Switch will
send an authentication request to the second tacacs host in the
server group and so on, until the list is exhausted. At that point, the
Switch will restart the same sequence with the following protocol
listed, xtacacs. If no authentication takes place using the xtacacs
list, the local account database set in the Switch is used to
authenticate the user. When the local method is used, the privilege
level will be dependant on the local account privilege configured on
the Switch.
Successful login using any of these methods will give the user a
“user” priviledge only. If the user wishes to upgrade his or her status
to the administrator level, the user must implement the enable admin
command, followed by a previously configured password. (See the
enable admin part of this section for more detailed information,
concerning the enable admin command.)
Parameters default – The default method list for access authentication, as
defined by the user. The user may choose one or more of the
following authentication methods: