29.04.2019 Views

OS6860(E)_AOS_8.1.1.R01_Switch_Management_Guide

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Managing <strong>Switch</strong> Security<br />

<strong>Switch</strong> Security Overview<br />

<strong>Switch</strong> Security Overview<br />

<strong>Switch</strong> security features increase the security of the basic switch login process by allowing management<br />

only through particular interfaces for users with particular privileges. Login information and privileges<br />

may be stored on the switch and/or an external server, depending on the type of external server you are<br />

using and how you configure switch access.<br />

The illustration here shows the components of switch security:<br />

End User<br />

RADIUS or LDAP<br />

Server<br />

Servers supply login information<br />

about the user. User<br />

privilege information is also<br />

available on RADIUS and<br />

LDAP servers.<br />

login request<br />

Omni<strong>Switch</strong><br />

management interface<br />

local user<br />

database<br />

Authenticated <strong>Switch</strong> Access Setup<br />

An external RADIUS or LDAP server can supply both user login and authorization information. External<br />

servers may also be used for accounting, which includes logging statistics about user sessions. For information<br />

about configuring the switch to communicate with external servers, see the “Managing Authentication<br />

Servers” chapter in the Omni<strong>Switch</strong> <strong>AOS</strong> Release 8 Network Configuration <strong>Guide</strong>.<br />

If an external server is not available or is not configured, user login information and user authorization<br />

may be provided through the local user database on the switch. The user database is described in<br />

Chapter 6, “Managing <strong>Switch</strong> User Accounts.”<br />

Logging may also be accomplished directly on the switch. For information about configuring local<br />

logging for switch access, see “Configuring Accounting for ASA” on page 7-11. For complete details<br />

about local logging, see the “Using <strong>Switch</strong> Logging” chapter in the Omni<strong>Switch</strong> <strong>AOS</strong> Release 8 Network<br />

Configuration <strong>Guide</strong>.<br />

Omni<strong>Switch</strong> <strong>AOS</strong> Release 8 <strong>Switch</strong> <strong>Management</strong> <strong>Guide</strong> May 2014 page 7-3

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!