© Copyright Lenovo 2017 Contents 5
SecureShellandSecureCopy......................89
ConfiguringSSH/SCPFeaturesontheSwitch ..............90
ToEnableorDisabletheSSH
Feature...............90
ToEnableorDisableSCP .....................90
ConfiguringtheSCPAdministratorPassword.....
........90
UsingSSHandSCPClientCommands.................90
ToLogIntotheSwitchfromtheClient ..............
.90
ToCopytheSwitchConfigurationFiletotheSCPHost........91
ToLoadaSwitchConfigurationFilefromtheSCPHost.......91
ToApplyandSavetheConfiguration...........
....91
ToCopytheSwitchImageandBootFilestotheSCPHost ......92
ToLoadSwitchConfigurationFilesfromtheSCPHost ........92
SSHandSCPEncryptionofManagementMessages .......
....93
GeneratingRSAHostKeyforSSHAccess...............93
SSH/SCPIntegrat ionwithRADIUSAuthentication ...........93
SSH/SCPIntegrat ionwithTACACS+Authentication .....
.....93
EndUserAccessControl.........................94
ConsiderationsforConfiguringEndUserAccounts...........94
StrongPasswords
..........................94
UserAccessControlMenu .....................
.95
SettingUpUserIDs.......................95
DefiningaUser’sAccessLevel..................95
Validating
aUser’sConfiguration .................95
EnablingorDisablingaUser . ..................95
LockingAccounts .....
...................95
Re‐enablingLockedAccounts ...................96
ListingCurrentUsers ........
................96
LoggingIntoanEndUserAccount..................96
ProtectedMode ........
....................97
StackingMode...........................97
Chapter 5. Authentication & Authorization Protocols . . . . . . . . . 99
RADIUSAuthentication
andAuthorization...............100
HowRADIUSAuthenticationWorks................100
ConfiguringRADIUSontheSwitch.......
..........101
RADIUSAuthenticationFeaturesinEnterpriseNOS.......... 101
SwitchUserAccounts......................
.102
RADIUSAttributesforEnterpriseNOSUserPrivileges ........103
TACACS+Authentication....................... 104
HowTACACS+AuthenticationWorks.....
...........104
TACACS+AuthenticationFeaturesinEnterpriseNOS.........105
Authorization . ......................
.. 105
Backdoor ...........................106
Accounting....................
......106
CommandAuthorizationandLogging................107
TACACS+PasswordChange....................109
Configuring
TACACS+AuthenticationontheSwitch.........109
LDAPAuthenticationandAuthorization ................110
ConfiguringtheLDAPServer............
........ 110
ConfiguringLDAPAuthenticationontheSwitch...........111