02.10.2013 Views

FTOS Configuration Guide for the C-Series - Force10 Networks

FTOS Configuration Guide for the C-Series - Force10 Networks

FTOS Configuration Guide for the C-Series - Force10 Networks

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

If rejected by <strong>the</strong> AAA server, <strong>the</strong> command is not added to <strong>the</strong> running config, and messages similar to<br />

Message 5 are displayed.<br />

Message 5 <strong>Configuration</strong> Command Rejection<br />

04:07:48: %RPM0-P:CP %SEC-3-SEC_AUTHORIZATION_FAIL: Authorization failure Command<br />

authorization failed <strong>for</strong> user (denyall) on vty0 ( 10.11.9.209 )<br />

VTY Line and Access-Class <strong>Configuration</strong><br />

Various methods are available to restrict VTY access in <strong>FTOS</strong>. These depend on which au<strong>the</strong>ntication<br />

scheme you use — line, local, or remote:<br />

Table 11 VTY Access<br />

Au<strong>the</strong>ntication Method<br />

<strong>FTOS</strong> provides several ways to configure access classes <strong>for</strong> VTY lines, including:<br />

• VTY Line Local Au<strong>the</strong>ntication and Authorization on page 155<br />

• VTY Line Remote Au<strong>the</strong>ntication and Authorization on page 157<br />

VTY Line Local Au<strong>the</strong>ntication and Authorization<br />

<strong>FTOS</strong> retrieves <strong>the</strong> access class from <strong>the</strong> local database. To use this feature:<br />

1. Create a username<br />

2. Enter a password<br />

3. Assign an access class<br />

4. Enter a privilege level<br />

VTY access-class<br />

support?<br />

Username<br />

access-class<br />

support? Remote authorization support?<br />

Line YES NO NO<br />

Local NO YES NO<br />

TACACS+ YES NO YES (with <strong>FTOS</strong> 5.2.1.0 and later)<br />

RADIUS YES NO YES (with <strong>FTOS</strong> 6.1.1.0 and later)<br />

Line au<strong>the</strong>ntication can be assigned on a per-VTY basis; it is a simple password au<strong>the</strong>ntication, using an<br />

access-class as authorization.<br />

Local au<strong>the</strong>ntication is configured globally. You configure access classes on a per-user basis.<br />

<strong>FTOS</strong> <strong>Configuration</strong> <strong>Guide</strong>, version 7.7.1.0 155

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!