02.10.2013 Views

FTOS Configuration Guide for the C-Series - Force10 Networks

FTOS Configuration Guide for the C-Series - Force10 Networks

FTOS Configuration Guide for the C-Series - Force10 Networks

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

To view <strong>the</strong> password configured <strong>for</strong> a terminal, use <strong>the</strong> show config command in <strong>the</strong> LINE mode.<br />

Enabling and disabling privilege levels<br />

Enter <strong>the</strong> enable or enable privilege-level command in <strong>the</strong> EXEC privilege mode to set a user’s security<br />

level. If you do not enter a privilege level, <strong>FTOS</strong> sets it to 15 by default.<br />

To move to a lower privilege level, enter <strong>the</strong> command disable followed by <strong>the</strong> level-number you wish to<br />

set <strong>for</strong> <strong>the</strong> user in <strong>the</strong> EXEC privilege mode. If you enter disable without a level-number, your security<br />

level is 1.<br />

RADIUS<br />

Remote Au<strong>the</strong>ntication Dial-In User Service (RADIUS) is a distributed client/server protocol. This<br />

protocol transmits au<strong>the</strong>ntication, authorization, and configuration in<strong>for</strong>mation between a central RADIUS<br />

server and a RADIUS client (<strong>the</strong> <strong>Force10</strong> system). The system sends user in<strong>for</strong>mation to <strong>the</strong> RADIUS<br />

server and requests au<strong>the</strong>ntication of <strong>the</strong> user and password. The RADIUS server returns one of <strong>the</strong><br />

following responses:<br />

• Access-Accept—<strong>the</strong> RADIUS server au<strong>the</strong>nticates <strong>the</strong> user<br />

• Access-Reject—<strong>the</strong> RADIUS server does not au<strong>the</strong>nticate <strong>the</strong> user<br />

If an error occurs in <strong>the</strong> transmission or reception of RADIUS packets, <strong>the</strong> error can be viewed by enabling<br />

<strong>the</strong> debug radius command.<br />

Transactions between <strong>the</strong> RADIUS server and <strong>the</strong> client are encrypted (<strong>the</strong> users’ passwords are not sent in<br />

plain text). RADIUS uses UDP as <strong>the</strong> transport protocol between <strong>the</strong> RADIUS server host and <strong>the</strong> client.<br />

For more in<strong>for</strong>mation on RADIUS, refer to RFC 2865, Remote Au<strong>the</strong>ntication Dial-in User Service.<br />

RADIUS Au<strong>the</strong>ntication and Authorization<br />

<strong>FTOS</strong> supports RADIUS <strong>for</strong> user au<strong>the</strong>ntication (text password) at login and can be specified as one of <strong>the</strong><br />

login au<strong>the</strong>ntication methods in <strong>the</strong> aaa au<strong>the</strong>ntication login command.<br />

When configuring AAA authorization, you can configure to limit <strong>the</strong> attributes of services available to a<br />

user. When authorization is enabled, <strong>the</strong> network access server uses configuration in<strong>for</strong>mation from <strong>the</strong><br />

user profile to issue <strong>the</strong> user's session. The user’s access is limited based on <strong>the</strong> configuration attributes.<br />

RADIUS exec-authorization stores a user-shell profile and that is applied during user login. You may name<br />

<strong>the</strong> relevant named-lists with ei<strong>the</strong>r a unique name or <strong>the</strong> default name. When authorization is enabled by<br />

<strong>the</strong> RADIUS server, <strong>the</strong> server returns <strong>the</strong> following in<strong>for</strong>mation to <strong>the</strong> client:<br />

• Idle time<br />

• ACL configuration in<strong>for</strong>mation<br />

• Auto-command<br />

<strong>FTOS</strong> <strong>Configuration</strong> <strong>Guide</strong>, version 7.7.1.0 145

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!