Contents
x
Catalyst 3750-E and 3560-E Switch Software Configuration Guide
OL-9775-08
CoA Request Commands 9-23
Stacking Guidelines for Session Termination 9-25
Configuring RADIUS 9-26
Default RADIUS Configuration 9-27
Identifying the RADIUS Server Host 9-27
Configuring RADIUS Login Authentication 9-29
Defining AAA Server Groups 9-31
Configuring RADIUS Authorization for User Privileged Access and Network Services 9-33
Starting RADIUS Accounting 9-34
Establishing a Session with a Router if the AAA Server is Unreachable 9-34
Configuring Settings for All RADIUS Servers 9-35
Configuring the Switch to Use Vendor-Specific RADIUS Attributes 9-35
Configuring the Switch for Vendor-Proprietary RADIUS Server Communication 9-37
Configuring CoA on the Switch 9-38
Monitoring and Troubleshooting CoA Functionality 9-39
Configuring RADIUS Server Load Balancing 9-39
Displaying the RADIUS Configuration 9-39
Controlling Switch Access with Kerberos 9-39
Understanding Kerberos 9-40
Kerberos Operation 9-42
Authenticating to a Boundary Switch 9-42
Obtaining a TGT from a KDC 9-42
Authenticating to Network Services 9-42
Configuring Kerberos 9-43
Configuring the Switch for Local Authentication and Authorization 9-43
Configuring the Switch for Secure Shell 9-45
Understanding SSH 9-45
SSH Servers, Integrated Clients, and Supported Versions 9-45
Limitations 9-46
Configuring SSH 9-46
Configuration Guidelines 9-46
Setting Up the Switch to Run SSH 9-46
Configuring the SSH Server 9-47
Displaying the SSH Configuration and Status 9-48
Configuring the Switch for Secure Socket Layer HTTP 9-49
Understanding Secure HTTP Servers and Clients 9-49
Certificate Authority Trustpoints 9-49
CipherSuites 9-51
Configuring Secure HTTP Servers and Clients 9-51