Cisco DS-C9216I-K9 Configuration Manual page 206

Switch guide
Table of Contents

Advertisement

Authentication and Authorization Process
Figure 18-1
Access
permitted
Denied
access
Step 1
When you can log in to the required switch in the Cisco MDS 9000 Family, you have the option to use
the Telnet, SSH, or Console login options.
Step 2
When you configure server groups using the server group authentication method, an authentication
request is sent to the first AAA server in the group.
If the AAA server fails to respond, then the next AAA server will be tried and so on until the remote
server responds to the authentication request.
If all AAA servers in the server group fail to respond, then the servers in the next server group are
tried.
If all configured methods fails, then local database is used for authentication.
Cisco MDS 9000 Fabric Manager Switch Configuration Guide
18-10
Switch Authorization and Authentication Flow
Success
None
Local user
name only
Failure
Found a RADIUS server
Accept
Failure
Radius
lookup
No response
Chapter 18
Start
Local
Local
Incoming
database
access
lookup
request to
switch
First or
next server
No more server
group
groups left
lookup
Found a server group
First or
next server
lookup
Found a TACACS+ server
Accept
Access
TACACS+
permitted
lookup
Configuring Switch Security
Success
Access
permitted
Failure
Failure
Denied
access
No response
OL-7753-01

Advertisement

Table of Contents
loading

Table of Contents