System information
User Authentication Commands
4-69
4
User Authentication Commands
You can configure this switch to authenticate users logging into the system for
management access using local or remote authentication methods. You can also
enable port-based authentication for network client access using IEEE 802.1X.
User Account Commands
The basic commands required for management access are listed in this section.
This switch also includes other options for password checking via the console or a
Telnet connection (page 4-31), user authentication via a remote authentication
server (page 4-69), and host access authentication for specific ports (page 4-93).
username
This command adds named users, requires authentication at login, specifies or
changes a user's password (or specify that no password is required), or specifies or
changes a user's access level. Use the no form to remove a user name.
Syntax
username name {access-level level | nopassword |
password {0 | 7} password}
no username name
• name - The name of the user.
(Maximum length: 8 characters, case sensitive. Maximum users: 16)
Table 4-24 Authentication Commands
Command Group Function Page
User Accounts Configures the basic user names and passwords for management
access
4-69
Authentication Sequence Defines logon authentication method and precedence 4-71
RADIUS Client Configures settings for authentication via a RADIUS server 4-73
TACACS+ Client Configures settings for authentication via a TACACS+ server 4-77
Web Server Settings Enables management access via a web browser 4-79
Telnet Server Settings Enables management access via Telnet 4-81
Secure Shell Settings Provides secure replacement for Telnet 4-82
Port Security Configures secure addresses for a port 4-92
Port Authentication Configures host authentication on specific ports using 802.1X 4-93
IP Filter Configures IP addresses that are allowed management access 4-102
Table 4-25 User Access Commands
Command Function Mode Page
username Establishes a user name-based authentication system at login GC 4-69
enable password Sets a password to control access to the Privileged Exec level GC 4-70