HP PROCURVE 6208M-SX Installation And Getting Started Manual page 81

Hewlett-packard switch user manual
Hide thumbs Also See for PROCURVE 6208M-SX:
Table of Contents

Advertisement

Installation and Getting Started Guide
Method Parameter
radius
none
NOTE: For examples of how to define authentication-method lists for types of authentication other than
TACACS/TACACS+, see "Configuring Authentication-Method Lists" on page 3-44.
Configuring TACACS+ Authorization
HP devices support TACACS+ authorization for controlling access to management functions in the CLI.
kinds of TACACS+ authorization are supported:
Exec authorization determines a user's privilege level when they are authenticated
Command authorization consults a TACACS+ server to get authorization for commands entered by the user
Configuring Exec Authorization
When TACACS+ exec authorization is performed, the HP device consults a TACACS+ server to determine the
privilege level of the authenticated user. To configure TACACS+ exec authorization on the HP device, enter the
following command:
HP9300(config)# aaa authorization exec default tacacs+
Syntax: aaa authorization exec default tacacs+ | none
Configuring an Attribute-Value Pair on the TACACS+ Server
During TACACS+ exec authorization, the TACACS+ server sends the HP device a response containing an A-V
(Attribute-Value) pair that specifies the privilege level of the user. When it receives the response, the HP device
extracts the first A-V pair configured for the Exec service and uses it to determine the user's privilege level.
To set a user's privilege level, you configure an A-V pair for the Exec service on the TACACS+ server that specifies
the user's privilege level. For example:
user=bob {
default service = permit
member admin
# Global password
global = cleartext "cat"
service = exec {
privlvl = 0
}
}
In this example, the first A-V pair configured for the Exec service is privlvl = 0, which grants the user full read­
write access. The Attribute name in the A-V pair is not significant. The Value must be an integer (0, 4, or 5) that
indicates the privilege level of the user. When no privilege level is specified, the default privilege level of 5 (read­
only) is used. The A-V pair can also be embedded in the group configuration for the user. See your TACACS+
documentation for the configuration syntax relevant to your server.
Configuring Command Authorization
When TACACS+ command authorization is enabled, the HP device consults a TACACS+ server to get
authorization for commands entered by the user.
3 - 24
Table 3.2: Authentication Method Values (Continued)
Description
Authenticate using the database on a RADIUS server. You also must
identify the server to the device using the radius-server command.
Do not use any authentication method. The device automatically
permits access.
Two

Advertisement

Table of Contents
loading

This manual is also suitable for:

Procurve 1600m

Table of Contents