Table 6: Default Tacacs+ Authorization Levels; Table 7: Alternate Tacacs+ Authorization Levels - Juniper EX2500 Configuration Manual

Juniper networks switch user manual
Hide thumbs Also See for EX2500:
Table of Contents

Advertisement

The default mapping between TACACS+ authorization levels and EX2500
management access levels is shown in Table 6. The authorization levels must be
defined on the TACACS+ server.

Table 6: Default TACACS+ Authorization Levels

EX2500 User Access Level
user
oper
admin
Alternate mapping between TACACS+ authorization levels and EX2500
management access levels is shown in Table 7. Use the following command to set
the alternate TACACS+ authorization levels:
ex2500(config)#
tacacs-server privilege-mapping

Table 7: Alternate TACACS+ Authorization Levels

EX2500 User Access Level
user
oper
admin
If the remote user is successfully authenticated by the authentication server, the
switch verifies the privileges of the remote user and authorizes the appropriate
access. The administrator has an option to allow secure backdoor access via Telnet
or SSH. Secure backdoor provides switch access when the TACACS+ servers
cannot be reached. You always can access the switch via the console port by using
notacacs and the administrator password, whether secure backdoor is enabled or
not.
To obtain the TACACS+ backdoor password for your EX2500 switch,
NOTE:
contact technical support.
Accounting
Accounting is the action of recording a user's activities on the device for the
purposes of billing and/or security. It follows the authentication and authorization
actions. If the authentication and authorization are not performed via TACACS+,
no TACACS+ accounting messages are sent out. The EX2500 switch supports the
following TACACS+ accounting attributes:
(console, telnet, ssh, or http)
protocol
start_time
stop_time
elapsed_time
disc_cause
TACACS+ level
0
3
6
TACACS+ level
0 - 1
6 - 8
14 - 15
Chapter 1: Accessing the Switch
Securing Access to the Switch
15

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents