H3C S5500-HI Series Fundamentals Configuration Manual page 29

Hide thumbs Also See for S5500-HI Series:
Table of Contents

Advertisement

Authentication
Meaning
mode
Local password
local
authentication
Remote AAA
authentication
scheme
through
HWTACACS or
RADIUS
Performs the local
password
authentication first
local scheme
and then the
remote AAA
authentication
Performs remote
AAA
authentication first
scheme local
and then the local
password
authentication
Follow these steps to set the authentication mode for user privilege level switching:
To do...
Enter system view
Set the authentication mode for
user privilege level switching
Configure the password for user
privilege level switching
Description
The switch authenticates a user by using the privilege level switching
password entered by the user.
When this mode is applied, you need to set the password for
privilege level switching with the super password command.
The switch sends the username and password for privilege level
switching to the HWTACACS or RADIUS server for remote
authentication.
When this mode is applied, you need to perform the following
configurations:
Configure HWTACACS or RADIUS scheme and reference the
created scheme in the ISP domain. For more information, see
Security Configuration Guide.
Create the corresponding user and configure password on the
HWTACACS or RADIUS server.
The switch authenticates a user by using the local password first,
and if no password for privilege level switching is set, for the user
logged in from the AUX user interface, the privilege level is switched
directly; for the user logged in from a VTY user interface, the AAA
authentication is performed.
AAA authentication is performed first, and if the remote
HWTACACS or RADIUS server does not respond or AAA
configuration on the switch is invalid, the local password
authentication is performed.
Use the command...
system-view
super authentication-mode { local
| scheme } *
super password [ level user-level ]
{ simple | cipher } password
18
Remarks
Optional
local by default.
Required if the authentication
mode is set to local (specify the
local keyword when setting the
authentication mode)
By default, no privilege level
switching password is configured.

Advertisement

Table of Contents
loading

Table of Contents