Specifications
Administrative AAA Configuration Scenarios
RoamAbout Mobility System Software Configuration Guide 3-7
Authenticating at the Console
Youcanconfiguretheconsolesothatauthentication isrequired,orsothatnoauthenticationis
required.Enterasys Networksrecommendsthatyouenforceauthenticationontheconsoleport.
Toenforceconsoleauthentication,takethefollowingsteps:
1. Addauserinthelocaldatabasebytypingthe followingcommandwithausernameand
password:
RBT-8100# set user username password password
2. Toenforcetheuseofconsoleauthenticationviathelocaldatabase,typethefollowing
command:
RBT-8100# set authentication console * local
3. Tostorethisconfigurationintononvolatilememory,typethefollowingcommand:
RBT-8100# save config
Bydefault,noauthenticationisrequiredattheconsole.Ifyouhavepreviouslyrequired
authenticationandhavedecidednottorequireit(duringtesting,forexample),typethefollowing
commandtoconfiguretheconsolesothatitdoesnotrequireusernameandpassword
authentication:
RBT-8100# set authentication console * none
Customizing AAA with “Globs” and Groups
“Globbing”letsyouclassifyusersbyusernameormediaaccesscontrol(MAC)addressfor
differentAAAtreatments.Auserglobisastring,possiblycontainingwildcards,formatching
AAAandIEEE802.1Xauthenticationmethodstoauserorsetofusers.TheRoa mAboutSwitch
supportsthefollowingwildcardcharacters foruser
globs:
•Singleasterisk(*)matchesthecharactersinausernameuptobutnotincludingaseparator
character,whichcanbeanat(@)signoraperiod(.).
•Doubleasterisk(**)matchesallusernames.
Inasimilarfashion,MACaddressglobsmatchauthenticationmethodstoaMACaddressorset
of
MACaddresses.Fordetails,see“UserGlobs,MACAddressGlobs,andVLANGlobs”on
page 1‐4.
AusergroupisanamedcollectionofusersorMACaddressessharingacommonauthorization
policy.Forexam ple,youmightgroupallusersonthefirstfloorofbuilding 17intothegroup
bldg
‐17‐1st‐floor,orgroupallusersintheITgroupintothegroupinfotech‐people.Individualuser
entriesoverridegroupentriesiftheybothconfigurethesameattribute.
Note: If you type this command before you have created a local username and password, you can
lock yourself out of the RoamAbout Switch. Before entering this command, you must configure a
local username and password.
Note: The authentication method none you can specify for administrative access is different from
the fallthru authentication type None, which applies only to network access. The authentication
method none allows access to the RoamAbout Switch by an administrator. The fallthru
authentication type None denies access to a network user. (For information about the fallthru
authentication types, see “Authentication Algorithm” on page 17-3.)