Contents
x
Cisco IE 3000 Switch Software Configuration Guide
OL-13018-03
Starting TACACS+ Accounting 11-17
Displaying the TACACS+ Configuration 11-17
Controlling Switch Access with RADIUS 11-17
Understanding RADIUS 11-18
RADIUS Operation 11-19
Configuring RADIUS 11-19
Default RADIUS Configuration 11-20
Identifying the RADIUS Server Host 11-20
Configuring RADIUS Login Authentication 11-23
Defining AAA Server Groups 11-25
Configuring RADIUS Authorization for User Privileged Access and Network Services 11-27
Starting RADIUS Accounting 11-28
Configuring Settings for All RADIUS Servers 11-29
Configuring the Switch to Use Vendor-Specific RADIUS Attributes 11-29
Configuring the Switch for Vendor-Proprietary RADIUS Server Communication 11-31
Configuring RADIUS Server Load Balancing 11-31
Displaying the RADIUS Configuration 11-32
Configuring the Switch for Local Authentication and Authorization 11-32
Configuring the Switch for Secure Shell 11-33
Understanding SSH 11-33
SSH Servers, Integrated Clients, and Supported Versions 11-33
Limitations 11-34
Configuring SSH 11-34
Configuration Guidelines 11-34
Setting Up the Switch to Run SSH 11-35
Configuring the SSH Server 11-36
Displaying the SSH Configuration and Status 11-37
Configuring the Switch for Secure Socket Layer HTTP 11-37
Understanding Secure HTTP Servers and Clients 11-37
Certificate Authority Trustpoints 11-38
CipherSuites 11-39
Configuring Secure HTTP Servers and Clients 11-40
Default SSL Configuration 11-40
SSL Configuration Guidelines 11-40
Configuring a CA Trustpoint 11-40
Configuring the Secure HTTP Server 11-41
Configuring the Secure HTTP Client 11-43
Displaying Secure HTTP Server and Client Status 11-43
Configuring the Switch for Secure Copy Protocol 11-44