Using The Aaa Subsystem To Control Management Access - HP ProCurve Secure 7000dl Series Basic Management And Configuration Manual

Secure router procurve 7000dl series
Hide thumbs Also See for ProCurve Secure 7000dl Series:
Table of Contents

Advertisement

Configuring Passwords to Control Management Access to the Router
Using the AAA Subsystem to Control Management
Access
Authentication, authorization, and accounting (AAA) is an industry standard
for controlling:
which users can access a system (authentication)
what they can do once they are granted access (authorization)
what is recorded about their activities (accounting)
The AAA subsystem on the ProCurve Secure Router currently supports
authentication using a remote Remote Authentication Dial-In User Service
(RADIUS) server. The ProCurve Secure Router also supports authentication,
authorization, and accounting using a remote TACACS+ server.
When you enable the AAA subsystem, you can specify a list of authentication
methods for each type of access. If one authentication method fails, the
ProCurve Secure Router will allow the user to try another access method.
The ProCurve Secure Router has specific criteria for failure:
Line and enable passwords fail if there are no line or enable passwords
configured.
RADIUS and TACACS+ servers fail if the ProCurve Secure Router cannot
reach the server on the network.
The local user list fails if the given user is not in the database.
For example, if you configure the authentication methods with RADIUS as the
first option and the RADIUS server goes down, the AAA subsystem tries the
next authentication method you configured. If you listed the local user list
after the RADIUS server, the AAA subsystem will use that authentication
method next.
However, if a user enters the wrong username or the wrong password for a
particular username, the user failed to authenticate to the router; the access
method did not fail. In this case, the user will be denied access to the router.
You can use the Web browser interface to specify the RADIUS and TACACS+
servers that the ProCurve Secure Router can contact. You can also configure
authentication using RADIUS or TACACS+ from the Web browser interface.
However, you must configure authorization and accounting using TACACS+
from the CLI.
Using the Web Browser Interface for Basic Configuration Tasks
14-27

Advertisement

Table of Contents
loading

This manual is also suitable for:

Procurve 7102dl seriesProcurve 7103dl series

Table of Contents