Contents
viii
Catalyst 2960 Switch Software Configuration Guide
OL-8603-04
Starting TACACS+ Accounting 8-17
Displaying the TACACS+ Configuration 8-17
Controlling Switch Access with RADIUS 8-17
Understanding RADIUS 8-18
RADIUS Operation 8-19
Configuring RADIUS 8-19
Default RADIUS Configuration 8-20
Identifying the RADIUS Server Host 8-20
Configuring RADIUS Login Authentication 8-23
Defining AAA Server Groups 8-25
Configuring RADIUS Authorization for User Privileged Access and Network Services 8-27
Starting RADIUS Accounting 8-28
Configuring Settings for All RADIUS Servers 8-29
Configuring the Switch to Use Vendor-Specific RADIUS Attributes 8-29
Configuring the Switch for Vendor-Proprietary RADIUS Server Communication 8-31
Displaying the RADIUS Configuration 8-31
Configuring the Switch for Local Authentication and Authorization 8-32
Configuring the Switch for Secure Shell 8-33
Understanding SSH 8-33
SSH Servers, Integrated Clients, and Supported Versions 8-33
Limitations 8-34
Configuring SSH 8-34
Configuration Guidelines 8-34
Setting Up the Switch to Run SSH 8-35
Configuring the SSH Server 8-36
Displaying the SSH Configuration and Status 8-37
Configuring the Switch for Secure Socket Layer HTTP 8-37
Understanding Secure HTTP Servers and Clients 8-37
Certificate Authority Trustpoints 8-38
CipherSuites 8-39
Configuring Secure HTTP Servers and Clients 8-40
Default SSL Configuration 8-40
SSL Configuration Guidelines 8-40
Configuring a CA Trustpoint 8-40
Configuring the Secure HTTP Server 8-41
Configuring the Secure HTTP Client 8-43
Displaying Secure HTTP Server and Client Status 8-43
Configuring the Switch for Secure Copy Protocol 8-43
Information About Secure Copy 8-44