02.10.2013 Views

FTOS Configuration Guide for the C-Series - Force10 Networks

FTOS Configuration Guide for the C-Series - Force10 Networks

FTOS Configuration Guide for the C-Series - Force10 Networks

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Configuring AAA Au<strong>the</strong>ntication login methods<br />

To configure an au<strong>the</strong>ntication method and method list, use <strong>the</strong>se commands in <strong>the</strong> following sequence in<br />

<strong>the</strong> CONFIGURATION mode:<br />

Step Command Syntax Command Mode Purpose<br />

1 aaa au<strong>the</strong>ntication login<br />

{method-list-name | default} method1<br />

[... method4]<br />

2<br />

3<br />

line {aux 0 | console 0 | vty number<br />

[... end-number]}<br />

login au<strong>the</strong>ntication<br />

{method-list-name | default}<br />

CONFIGURATION Define an au<strong>the</strong>ntication method-list<br />

(method-list-name) or specify <strong>the</strong><br />

default. The default method-list is<br />

applied to all terminal lines.<br />

Possible methods are:<br />

• enable—use <strong>the</strong> password defined<br />

by <strong>the</strong> enable secret or enable<br />

password command in <strong>the</strong><br />

CONFIGURATION mode.<br />

• line—use <strong>the</strong> password defined by<br />

<strong>the</strong> password command in <strong>the</strong> LINE<br />

mode.<br />

• local—use <strong>the</strong> username/password<br />

database defined in <strong>the</strong> local<br />

configuration.<br />

• none—no au<strong>the</strong>ntication.<br />

• radius—use <strong>the</strong> RADIUS server(s)<br />

configured with <strong>the</strong> radius-server host<br />

command.<br />

• tacacs+—use <strong>the</strong> TACACS+<br />

server(s) configured with <strong>the</strong><br />

tacacs-server host command<br />

CONFIGURATION Enter <strong>the</strong> LINE mode.<br />

LINE Assign a method-list-name or <strong>the</strong> default<br />

list to <strong>the</strong> terminal line.<br />

<strong>FTOS</strong> Behavior: If you use a method list on <strong>the</strong> console port in which RADIUS or TACACS is <strong>the</strong> last<br />

au<strong>the</strong>ntication method, and <strong>the</strong> server is not reachable, <strong>FTOS</strong> allows access even though <strong>the</strong><br />

username and password credentials cannot be verified. Only <strong>the</strong> console port behaves this way, and<br />

does so to ensure that users are not locked out of <strong>the</strong> system in <strong>the</strong> event that network-wide issue<br />

prevents access to <strong>the</strong>se servers.<br />

To view <strong>the</strong> configuration, use <strong>the</strong> show config command in <strong>the</strong> LINE mode or <strong>the</strong> show running-config<br />

in <strong>the</strong> EXEC privilege mode.<br />

Note: <strong>Force10</strong> <strong>Networks</strong> recommends that you use <strong>the</strong> none method only as a backup. This<br />

method does not au<strong>the</strong>nticate users. The none and enable methods do not work with SSH.<br />

You can create multiple method lists and assign <strong>the</strong>m to different terminal lines.<br />

<strong>FTOS</strong> <strong>Configuration</strong> <strong>Guide</strong>, version 7.7.1.0 137

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!