Contents
viii
Catalyst 2950 and Catalyst 2955 Switch Software Configuration Guide
78-11380-12
Protecting Enable and Enable Secret Passwords with Encryption 8-4
Disabling Password Recovery 8-5
Setting a Telnet Password for a Terminal Line 8-6
Configuring Username and Password Pairs 8-7
Configuring Multiple Privilege Levels 8-8
Setting the Privilege Level for a Command 8-8
Changing the Default Privilege Level for Lines 8-9
Logging into and Exiting a Privilege Level 8-10
Controlling Switch Access with TACACS+ 8-10
Understanding TACACS+ 8-10
TACACS+ Operation 8-12
Configuring TACACS+ 8-12
Default TACACS+ Configuration 8-13
Identifying the TACACS+ Server Host and Setting the Authentication Key 8-13
Configuring TACACS+ Login Authentication 8-14
Configuring TACACS+ Authorization for Privileged EXEC Access and Network Services 8-16
Starting TACACS+ Accounting 8-17
Displaying the TACACS+ Configuration 8-17
Controlling Switch Access with RADIUS 8-17
Understanding RADIUS 8-18
RADIUS Operation 8-19
Configuring RADIUS 8-20
Default RADIUS Configuration 8-20
Identifying the RADIUS Server Host 8-20
Configuring RADIUS Login Authentication 8-23
Defining AAA Server Groups 8-25
Configuring RADIUS Authorization for User Privileged Access and Network Services 8-27
Starting RADIUS Accounting 8-28
Configuring Settings for All RADIUS Servers 8-29
Configuring the Switch to Use Vendor-Specific RADIUS Attributes 8-29
Configuring the Switch for Vendor-Proprietary RADIUS Server Communication 8-30
Displaying the RADIUS Configuration 8-31
Configuring the Switch for Local Authentication and Authorization 8-32
Configuring the Switch for Secure Shell 8-33
Understanding SSH 8-33
SSH Servers, Integrated Clients, and Supported Versions 8-33
Limitations 8-34
Configuring SSH 8-34
Configuration Guidelines 8-34