Operating Notes - HP 3500yl Series Access Security Manual

Switch software
Hide thumbs Also See for 3500yl Series:
Table of Contents

Advertisement

TACACS+ Authentication

Operating Notes

5-30
Operating Notes
If you configure Authorized IP Managers on the switch, it is not
necessary to include any devices used as TACACS+ servers in the
authorized manager list. That is, authentication traffic between a
TACACS+ server and the switch is not subject to Authorized IP
Manager controls configured on the switch. Also, the switch does not
attempt TACACS+ authentication for a management station that the
Authorized IP Manager list excludes because, independent of
TACACS+, the switch already denies access to such stations.
When TACACS+ is not enabled on the switch—or when the switch's
only designated TACACS+ servers are not accessible— setting a local
Operator password without also setting a local Manager password
does not protect the switch from manager-level access by unauthor-
ized persons.
When using the copy command to transfer a configuration to a TFTP
server, any optional, server-specific and global encryption keys (page
5-17) in the TACACS configuration will not be included in the trans-
ferred file. Otherwise, a security breach could occur, allowing access
to the TACACS+ username/password information.

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents