Cisco WS-C2948G-GE-TX Configuration Manual page 484

Catalyst 4500 series switch
Table of Contents

Advertisement

Configuring Authentication
This example shows how to clear the DES key:
Console> (enable) clear key config-key
Kerberos config key cleared
Console> (enable)
Encrypting a Telnet Session
After a user authenticates to the switch using Kerberos and wants to Telnet to a different switch or host,
the authentication method that the Telnet server uses determines if the new session is a Kerberized Telnet
session. If the Telnet server uses Kerberos for authentication, you can have all the application data
packets encrypted for the duration of the Telnet session. To encrypt the Telnet session, select the encrypt
kerberos option in the telnet command.
To encrypt a Telnet session, perform this task in privileged mode:
Task
Encrypt a Telnet session.
This example shows how to configure a Telnet session for Kerberos authentication and encryption:
Console> (enable) telnet encrypt kerberos 172.20.52.5
Monitoring and Maintaining Kerberos
Use these commands to display and clear Kerberos configurations on the switch:
To display the Kerberos configuration, perform this task in privileged mode:
Task
Display the Kerberos configuration.
This example shows how to display the Kerberos configuration:
Console> (enable) show kerberos
Kerberos Local Realm:CISCO.COM
Kerberos server entries:
Realm:CISCO.COM,
Realm:CISCO.COM,
Kerberos Domain<->Realm entries:
Domain:cisco.com,
Kerberos Clients NOT Mandatory
Kerberos Credentials Forwarding Enabled
Kerberos Pre Authentication Method set to None
Kerberos config key:
Kerberos SRVTAB Entries
Srvtab Entry 1:host/niners.cisco.com@CISCO.COM 0 932423923 1 1 8 03;;5>00>50;0=0=0
Srvtab Entry 2:host/niners.cisco.edu@CISCO.EDU 0 933974942 1 1 8 00?58:127:223=:;9
Console> (enable)
Catalyst 4500 Series, Catalyst 2948G, Catalyst 2948G-GE-TX, and Catalyst 2980G Switches Software Configuration Guide—Release 8.2GLX
30-38
show kerberos
show kerberos creds
clear kerberos creds
Server:187.0.2.1,
Server:187.20.2.1,
Realm:CISCO.COM
Chapter 30
Command
telnet [encrypt kerberos] host
Command
show kerberos
Port:750
Port:750
Configuring Switch Access Using AAA
78-15908-01

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents