Specifications

SecureStack B2 Configuration Guide 19-1
19
Authentication and Authorization
Configuration
Thischapterdescribestheauthenticationandauthorizationcommandsandhowtousethem.
Overview of Authentication and Authorization Methods
Thefollowingmethodsareavailableforcontrollingwhichusersareallowedtoaccess,monitor,
andmanagetheswitch.
•LoginuseraccountsandpasswordsusedtologintotheCLIviaaTelnetconnectionorlocal
COMportconnection.Fordetails,refertoSettingUserAccountsandPasswordson
page 3 2.
•HostAccessControlAuthentication(HACA)authenticatesuseraccessofTelnet
management,consolelocalmanagementandWebViewviaacentralRADIUSClient/Server
application.WhenRADIUSisenabled,thisessentiallyoverridesloginuseraccounts.When
HACAisactiveperavalidRADIUSconfiguration,theusernamesandpasswordsusedto
accesstheswitchviaTelnet,SSH,WebView,andCOMportswillbevalida tedagainst the
configuredRADIUSserver.OnlyinthecaseofaRADIUStimeoutwillthosecredentialsbe
comparedagainstcredentialslocallyconfiguredontheswitch.
Fordetails,referto
ConfiguringRADIUSonpage 193.
•SNMPuserorcommunitynamesallowsaccesstotheSecureStackB2switchviaanetwork
SNMPmanagementapplication.Toaccesstheswitch, youmustenteranSNMPuseror
communitynamestring.Thelevelofmanagementaccessisdependenton
theassociated
accesspolicy.Fordetails,refertoChapter 8.
For information about... Refer to page...
Overview of Authentication and Authorization Methods 19-1
Configuring RADIUS 19-3
Configuring 802.1X Authentication 19-11
Configuring MAC Authentication 19-21
Configuring Multiple Authentication Methods 19-33
Configuring VLAN Authorization (RFC 3580) 19-45
Configuring MAC Locking 19-50
Configuring Port Web Authentication (PWA) 19-61
Configuring Secure Shell (SSH) 19-73