Aaa Server Monitoring - HP Cisco MDS 9216 - Fabric Switch Configuration Manual

Cisco mds 9000 family fabric manager configuration guide, release 3.x (ol-8222-10, april 2008)
Hide thumbs Also See for Cisco MDS 9216 - Fabric Switch:
Table of Contents

Advertisement

Chapter 41
Configuring RADIUS and TACACS+
S e n d d o c u m e n t a t i o n c o m m e n t s t o m d s f e e d b a c k - d o c @ c i s c o . c o m
Caution
Cisco MDS SAN-OS does not support all numeric usernames, whether created with TACACS+ or
RADIUS, or created locally. Local username with all numerics cannot be created. If an all numeric
username exists on an AAA server and is entered during login, the user is not logged in.
Even if local is not specified as one of the options, it is tried when all other configured options fail.
Note
When RADIUS times out, local login is always attempted. For this local login to be successful, a local
account for the user with the same password should exist, and the RADIUS timeout and retries should
take less than 40 seconds. The user is authenticated if the username and password exist in the local
authentication configuration.

AAA Server Monitoring

An unresponsive AAA server introduces a delay in the processing of AAA requests. An MDS switch can
periodically monitor an AAA server to check whether it is responding (or alive) to save time in
processing AAA requests. The MDS switch marks unresponsive AAA servers as dead and does not send
AAA requests to any dead AAA servers. An MDS switch periodically monitors dead AAA servers and
brings them to the alive state once they are responding. This monitoring process verifies that an AAA
server is in a working state before real AAA requests are sent its way. Whenever an AAA server changes
to the dead or alive state, an SNMP trap is generated and the MDS switch warns the administrator that
a failure is taking place before it can impact performance. See
Figure 41-1
Alive
The monitoring interval for alive servers and dead servers is different and can be configured by the user.
Note
The AAA server monitoring is performed by sending a test authentication request to the AAA server.
The user name and password to be used in the test packet can be configured.
See the
OL-16184-01, Cisco MDS SAN-OS Release 3.x
AAA Server States
Alive and
used
Application
request
Alive and
Idle timer
testing
expired
Dead and
testing
"Configuring RADIUS Server Monitoring Parameters" section on page
Figure 41-1
Response from
Process
remote server
application
request
Test
AAA packets
sent
Test
Dead timer expired
Cisco MDS 9000 Family CLI Configuration Guide
Switch AAA
for AAA server states.
No
response
Dead
Directed
AAA request
41-7.
41-5

Advertisement

Table of Contents
loading

Table of Contents