Traffic Storm Control 7
Control Plane Policing 8
Rate Limits 8
Software Image 8
Virtual Device Contexts 8
Configuring AAA 9
CHAPTER 3
About AAA 9
AAA Security Services 9
Benefits of Using AAA 10
Remote AAA Services 10
AAA Server Groups 11
AAA Service Configuration Options 11
Authentication and Authorization Process for User Login 12
AES Password Encryption and Master Encryption Keys 13
Licensing Requirements for AAA 13
Prerequisites for AAA 14
Guidelines and Limitations for AAA 14
Default Settings for AAA 14
Configuring AAA 15
Process for Configuring AAA 15
Configuring Console Login Authentication Methods 15
Configuring Default Login Authentication Methods 17
Disabling Fallback to Local Authentication 19
Enabling the Default User Role for AAA Authentication 20
Enabling Login Authentication Failure Messages 21
Logging Successful and Failed Login Attempts 22
Enabling CHAP Authentication 23
Enabling MSCHAP or MSCHAP V2 Authentication 24
Configuring AAA Accounting Default Methods 26
Using AAA Server VSAs with Cisco NX-OS Devices 28
About VSAs 28
VSA Format 28
Specifying Cisco NX-OS User Roles and SNMPv3 Parameters on AAA Servers 29
Cisco Nexus 9000 Series NX-OS Security Configuration Guide, Release 9.x
iv
Contents