Specifications
DGS-3048 Layer 2 Switch CLI Reference Manual
125
19
ACCESS AUTHENTICATION CONTROL COMMANDS
Please note that user granted access to the Switch will be granted normal user privileges on the Switch. To gain
access to admin level privileges, the user must enter the enable admin command and then enter a password, which
was previously configured by the administrator of the Switch.
The Access Authentication Control commands let you secure access to the Switch using the TACACS+ and
RADIUS protocols. When a user logs in to the Switch or tries to access the administrator level privilege, he or she
is prompted for a password. If TACACS+ / RADIUS authentication is enabled on the Switch, it will contact a
TACACS+ / RADIUS server to verify the user. If the user is verified, he or she is granted access to the Switch.
The Switch’s software supports the following versions of TACACS:
• TACACS+ (Terminal Access Controller Access Control System plus) — Provides detailed access
control for authentication for network devices. TACACS+ is facilitated through Authentication commands via one
or more centralized servers. The TACACS+ protocol encrypts all traffic between the Switch and the TACACS+
daemon, using the TCP protocol to ensure reliable delivery.
The Switch also supports the RADIUS protocol for authentication using the Access Authentication Control
commands. RADIUS or Remote Authentication Dial In User Server also uses a remote server for authentication
and can be responsible for receiving user connection requests, authenticating the user and returning all
configuration information necessary for the client to deliver service through the user. RADIUS may be facilitated
on this Switch using the commands listed in this section.
In order for the TACACS+ security function to work properly, a TACACS+ server must be configured on a
device other than the Switch, called a server host and it must include usernames and passwords for authentication.
When the user is prompted by the Switch to enter usernames and passwords for authentication, the Switch contacts
the TACACS+ server to verify, and the server will respond with one of three messages:
A) The server verifies the username and password, and the user is granted normal user privileges on the
Switch.
B) The server will not accept the username and password and the user is denied access to the Switch.
C) The server doesn’t respond to the verification query. At this point, the Switch receives the timeout from
the server and then moves to the next method of verification configured in the method list.
The administrator for the Switch may set up 4 different authentication techniques per user-defined method list
(TACACS+ / RADIUS / local / none) for authentication. These techniques will be listed in an order preferable,
and defined by the user for normal user authentication on the Switch, and may contain up to eight authentication
techniques. When a user attempts to access the Switch, the Switch will select the first technique listed for
authentication. If the first technique goes through its server hosts and no authentication is returned, the Switch will
then go to the next technique listed in the server group for authentication, until the authentication has been verified
or denied, or the list is exhausted.
Please note that user granted access to the Switch will be granted normal user privileges on the Switch. To gain
access to admin level privileges, the user must enter the enable admin command and then enter a password, which
was previously configured by the administrator of the Switch.
The Access Authentication Control commands in the Command Line Interface (CLI) are listed (along with the
appropriate parameters) in the following table.
Command Parameters
create authen_login
method_list_name
<string 12>
config authen_login [default | method_list_name <string 12>] method {tacacs+ |
radius | local | none}
delete authen_login <string 12>