Specifications

Administrative AAA Configuration Scenarios
3-2 Configuring AAA for Administrative and Local Access
Enabledmode.Toentertheenabledmodeofoperation,youtypetheenablecommandatthe
commandprompt.Inenabledmode,youcanuseallCLIcommands.AlthoughMSSdoesnot
requireanenablepassword,Enterasys Networkshighlyrecommendsthatyousetone.
Customizedauthentication.Youcanrequireauthenticationforall
usersorforonlyasubsetof
users.Usernameglobbing(seeUserGlobs,MACAddressGlobs,andVLANGlobson
page 14)allowsdifferentusersorclassesofusertobegivendifferentauthentication
treatments.YoucanconfigureconsoleauthenticationandTelnetauthenticationseparately,
andyoucanapplydifferentauthentication
methodstoeach.
Foranyuser,authorizationusesthesamemethod(s)asauthenticationforthatuser.
Localoverride.Aspecialauthenticationtechniquecalledlocaloverrideletsyouattempt
authenticationviathelocaldatabasebeforeattemptingauthenticationviaaRADIUSserver.
TheRoamAboutSwitchattemptsadministrativeauthenticationinthelocaldatabasefirst.
Ifit
findsnomatch,theRoamAboutSwitchattemptsadministrativeauthenticationonthe
RADIUSserver.(ForinformationaboutsettingaRoamAboutSwitchtouseRADIUSservers,
seeChapter 18,ConfiguringCommunicationwithRADIUS.)
Accountingforadministrativeaccesssessions.Accountingrecordscanbestoredand
displayedlocallyorsenttoa
RADIUSserver.Accountingrecordsprovideanaudittrailofthe
timeanadministrativeuserloggedin,theadministratorsusername,thenumberofbytes
transferred,andthetimethesessionstartedandended.
Figure 31illustratesatypicalRoamAboutSwitch,accesspoints,andnetworkadministratorinan
enterprisenetwork.Asnetworkadministrator,
youinitiallyaccesstheRoamAboutSwitchviathe
console.Youcanthenoptionallyconfigureauthentication,authorization,and accountingfor
administrativeaccessmode.
Enterasys Networksrecommendsenforcingauthenticationforadministrativeaccessusing
usernamesandpasswordsstoredeitherlocallyoronRADIUSservers.