DES-3550 Layer 2 Fast Ethernet Switch User’s Guide
120
To view the following window, click Management > Access Authentication Control >
Authentication Server Group:
Figure 7- 7. Authentication Server Group Settings window
This screen displays the Authentication Server Groups on the Switch. The Switch has three
built-in Authentication Server Groups that cannot be removed but can be modified. To
modify a particular group, click its hyperlinked
Group Name
, which will then display the
following window.
Figure 7- 8. Add a Server Host to Server Group (tacacs) window.
To add an Authentication Server Host to the list, enter its IP address in the IP Address field,
choose the protocol associated with the IP address of the Authentication Server Host, and
click ADD to Group to add this Authentication Server Host to the group.
Authentication Server Hosts
This window will set user-defined Authentication Server Hosts for the
TACACS/XTACACS/TACACS+
security protocols on the Switch. When a user attempts to access
the Switch with Authentication Policy enabled, the Switch will send authentication packets to
a remote
TACACS/XTACACS/TACACS+ server host on a remote host. The
TACACS/XTACACS/TACACS+ server host will then verify or deny the request and return the
NOTE: The user must configure Authentication Server Hosts
using the Authentication Server Hosts window before adding hosts
to the list. Authentication Server Hosts must be configured for their
specific protocol on a remote centralized server before this
function can work properly.
NOTE:
The three built-in server groups on the Switch can only
have server hosts running the same TACACS daemon.
TACACS/XTACACS/TACACS+ protocols are separate entities
and are not compatible with each other.