19.10.2013 Views

7.6.1.0 - Force10 Networks

7.6.1.0 - Force10 Networks

7.6.1.0 - Force10 Networks

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Privilege Level<br />

Through the RADIUS server, you can use the command privilege level to configure a privilege level for<br />

the user to enter into when they connect to a session.This value is configured on the client system.<br />

Configuration Task List for RADIUS<br />

To authenticate users using RADIUS, at least one RADIUS server must be specified so that the E-Series<br />

cab communicate with and configure RADIUS as one of your authentication methods.<br />

The following list includes the configuration tasks for RADIUS.<br />

• define an aaa method list to be used for RADIUS on page 117 (mandatory)<br />

• apply the method list to terminal lines on page 118 (mandatory except when using default lists)<br />

• specify a RADIUS server host on page 118 (mandatory)<br />

• set global communication parameters for all RADIUS server hosts on page 119 (optional)<br />

• monitor RADIUS on page 120 (optional)<br />

For a complete listing of all commands related to RADIUS, refer to .<br />

Note: RADIUS authentication and authorization are done in a single step. Hence, authorization cannot<br />

be used independent of authentication. However, if RADIUS authorization is configured and<br />

authentication is not, then a message is logged stating this. During authorization, the next method in<br />

the list (if present) is used, or if another method is not present, an error is reported.<br />

To view the configuration, use the show config in the LINE mode or the show running-config command<br />

in the EXEC privilege mode.<br />

define an aaa method list to be used for RADIUS<br />

To configure RADIUS to authenticate or authorize users on the E-Series, you must create an AAA method<br />

list. Default-method-lists do not need to be explicitly applied to the line, hence, they are not-mandatory. To<br />

create a method list, enter either one of the following commands in CONFIGURATION mode:<br />

Command Syntax Command Mode Purpose<br />

aaa authentication login<br />

method-list-name radius<br />

aaa authorization exec<br />

{method-list-name | default} radius<br />

tacacs+<br />

CONFIGURATION Enter a text string (up to 16 characters long) as the<br />

name of the method list you wish to use with the<br />

RADIUS authentication method.<br />

CONFIGURATION Create methodlist with RADIUS and TACACS+ as<br />

authorization methods. Typical order of methods:<br />

RADIUS, TACACS+, Local, None. If authorization<br />

is denied by RADIUS, the session ends (radius<br />

should not be the last method specified).<br />

FTOS Configuration Guide, version <strong>7.6.1.0</strong> 117

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!