Configuring AAA 12
Configuring Console Login Authentication Methods 12
Configuring Default Login Authentication Methods 13
Enabling Login Authentication Failure Messages 14
Logging Successful and Failed Login Attempts 15
Configuring AAA Command Authorization 16
Enabling MSCHAP Authentication 17
Configuring AAA Accounting Default Methods 18
Using AAA Server VSAs 20
VSAs 20
VSA Format 20
Specifying Switch User Roles and SNMPv3 Parameters on AAA Servers 20
Secure Login Enhancements 21
Secure Login Enhancements 21
Configuring Login Parameters 21
Configuration Examples for Login Parameters 22
Restricting Sessions Per User—Per User Per Login 23
Enabling the Password Prompt for User Name 24
Configuring Share Key Value for using RADIUS/TACACS+ 24
Monitoring and Clearing the Local AAA Accounting Log 25
Verifying the AAA Configuration 25
Configuration Examples for AAA 26
Default AAA Settings 26
CHAPTER 4
Configuring RADIUS 29
Information About RADIUS 29
RADIUS Network Environments 29
Information About RADIUS Operations 30
RADIUS Server Monitoring 31
Vendor-Specific Attributes 31
Prerequisites for RADIUS 32
Guidelines and Limitations for RADIUS 32
Configuring RADIUS Servers 32
Configuring RADIUS Server Hosts 33
Configuring RADIUS Global Preshared Keys 34
Cisco Nexus 3600 NX-OS Security Configuration Guide, Release 7.x
iv
Contents