27.10.2013 Views

2.5.2 - Force10 Networks

2.5.2 - Force10 Networks

2.5.2 - Force10 Networks

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Chapter 8<br />

This chapter contains the following major sections:<br />

• Choosing a TACACS+ Server and Authentication Method<br />

• Configuring TACACS+ Server Connection Options on page 145<br />

• Configuring a RADIUS Connection on page 146<br />

• Enabling Secure Management with SSH on page 149<br />

SFTOS supports several user-access security methods to the switch, including local (see Creating a User<br />

and Password on page 45), port security (IEEE 802.1X) through RADIUS and Terminal Access Controller<br />

Access Control System (TACACS+), and encrypted transport session (between the management station<br />

and switch) using Secure Shell (SSH). This chapter describes how to configure each of those methods.<br />

For more on port security configuration (including MD5), see the Security deck of the S-Series Training<br />

slides, which are on the S-Series Documentation CD-ROM.<br />

Choosing a TACACS+ Server and Authentication Method<br />

To use TACACS+ to authenticate users, you specify at least one TACACS+ server with which the S-Series<br />

will communicate, then identify TACACS+ as one of your authentication methods. To select TACACS as<br />

the login authentication method, use the following command sequence:<br />

Step Command Syntax<br />

Providing User Access<br />

Security<br />

Command<br />

Mode Purpose<br />

1 tacacs-server host ip-address Global Config Configure a TACACS+ server host. Enter the IP<br />

address or host name of the TACACS+ server.<br />

You can use this command multiple times to<br />

configure multiple TACACS+ server hosts.<br />

1 exit TACACS<br />

Config<br />

Return to Global Config mode. Alternatively, while<br />

you are still in TACACS Config mode, you can set<br />

values for server-specific parameters, such as<br />

priority, key, and timeout. See Configuring<br />

TACACS+ Server Connection Options on<br />

page 145.<br />

SFTOS Configuration Guide, Version <strong>2.5.2</strong>.0 143

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!