EasyManua.ls Logo

Enterasys SecureStack C2 - Page 530

Enterasys SecureStack C2
607 pages
Print Icon
To Next Page IconTo Next Page
To Next Page IconTo Next Page
To Previous Page IconTo Previous Page
To Previous Page IconTo Previous Page
Loading...
set radius
18-6 Security Configuration
Defaults
Ifsecret‐valueisnotspecified,nonewillbeapplied.
Ifî ±realmî ±isî ±notî ±specified,î ±theî ±anyî ±accessî ±realmî ±willî ±beî ±used.
Mode
Switchcommand,read‐write.
Usage
Theî ±SecureStackî ±C2î ±deviceî ±allowsî ±upî ±toî ±10î ±RADIUSî ±accountingî ±serversî ±toî ±beî ±configured,î ±withî ±upî ±
toî ±twoî ±serversî ±activeî ±atî ±anyî ±givenî ±time.
Theî ±RADIUSî ±clientî ±canî ±onlyî ±beî ±enabledî ±onî ±theî ±switchî ±onceî ±aî ±RADIUSî ±serverî ±isî ±online,î ±andî ±itsî ±IPî ±
address(es)î ±hasî ±beenî ±configuredî ±withî ±theî ±sameî ±passwordî ±
theî ±RADIUSî ±clientî ±willî ±use.î ±
Examples
Thisî ±exampleî ±showsî ±howî ±toî ±enableî ±theî ±RADIUSî ±clientî ±forî ±authenticatingî ±withî ±RADIUSî ±serverî ±1î ±atî ±
IPî ±addressî ±192.168.6.203,î ±UDPî ±authenticationî ±portî ±1812,î ±andî ±anî ±authenticationî ±passwordî ±ofî ±
“pwsecret.”Aspreviouslynoted,the“serversecret”passwordenteredheremustmatchthat
alreadyconfiguredastheRead‐Write(rw)passwordonthe
î ±RADIUSî ±server:
C2(su)->set radius server 1 192.168.6.203 1812 pwsecret
Thisî ±exampleî ±showsî ±howî ±toî ±setî ±theî ±RADIUSî ±timeoutî ±toî ±5î ±seconds:
C2(su)->set radius timeout 5
Thisî ±exampleî ±showsî ±howî ±toî ±setî ±RADIUSî ±retriesî ±toî ±10:
C2(su)->set radius retries 10
Thisexampleshowshowtoforceanymanagement‐accesstotheswitch(Telnet,web,SSH)to
authenticateî ±throughî ±aî ±RADIUSî ±server.î ±Theî ±allî ±parameterî ±atî ±theî ±endî ±ofî ±theî ±commandî ±meansî ±thatî ±
anyî ±ofî ±theî ±definedî ±RADIUSî ±serversî ±canî ±beî ±usedî ±forî ±thisî ±Authentication.î ±
C2(rw)->set radius realm management-access all
realmî ±
management‐
accessî ±|î ±anyî ±|î ±
network‐access
Realmî ±allowsî ±youî ±toî ±defineî ±whoî ±hasî ±toî ±goî ±throughî ±theî ±RADIUSî ±serverî ±forî ±
authentication.
‱ management‐access:î ±Thisî ±meansî ±thatî ±anyoneî ±tryingî ±toî ±accessî ±theî ±switchî ±
(Telnet,î ±SSH,î ±Localî ±Management)î ±hasî ±toî ±authenticateî ±throughî ±theî ±
RADIUSî ±server.
‱ network‐access:î ±Thisî ±meansî ±thatî ±
allî ±theî ±usersî ±haveî ±toî ±authenticateî ±toî ±aî ±
RADIUSî ±serverî ±beforeî ±theyî ±areî ±allowedî ±accessî ±toî ±theî ±network.
‱ any:î ±Meansî ±thatî ±bothî ±management‐accessî ±andî ±network‐accessî ±haveî ±
beenî ±enabled.
Note: If the management-access or any access realm has been configured, the
local “admin” account is disabled for access to the switch using the console, Telnet,
or Local Management. Only the network-access realm allows access to the local
“admin” account.
indexî ±|î ±all Appliesî ±theî ±realmî ±settingî ±toî ±aî ±specificî ±serverî ±orî ±toî ±allî ±servers.
Note: If RADIUS is configured with no host IP address on the device, it will use the loopback
interface 0 IP address (if it has been configured) as its source for the NAS-IP attribute. For
information about configuring loopback interfaces, refer to “interface” on page 16-2.

Table of Contents

Related product manuals