Implementing Aaa/Radius On A Switch - H3C S9500 Series Operation Manual

Routing switches
Hide thumbs Also See for S9500 Series:
Table of Contents

Advertisement

Operation Manual – Security
H3C S9500 Series Routing Switches
User
User
Requests the user for
Requests the user for
username
username
The user inputs username
The user inputs username
Requests the user
Requests the user
for password
for password
User inputs the password
User inputs the password
The user logs on successfully
The user logs on successfully
Figure 2-2 Basic message exchange procedures

2.1.4 Implementing AAA/RADIUS on a Switch

By now, we understand that in the above-mentioned AAA/RADIUS framework, H3C
Series Switches, serving as the user access device (NAS), is the client end of RADIUS.
In other words, the AAA/RADIUS concerning client-end is implemented on H3C Series
Switches. Figure 2-3 illustrates the RADIUS authentication network including H3C
Series Switches.
TACACS
TACACS
Client
Client
User logs on
User logs on
Authentication response packet,
Authentication response packet,
Authentication continuance packet,
Authentication continuance packet,
sending password to the server
sending password to the server
Authentication response packet.
Authentication response packet.
Accounting start packet response
Accounting start packet response
User logs off
User logs off
Accounting stop packet response
Accounting stop packet response
Chapter 2 AAA and RADIUS/HWTACACS
Authentication start packet
Authentication start packet
requesting username
requesting username
Authentication continuance packet,
Authentication continuance packet,
sending username to the server
sending username to the server
Authentication response packet,
Authentication response packet,
requesting password
requesting password
Authentication succeeds
Authentication succeeds
Authorization request packet
Authorization request packet
Authorization response
Authorization response
packet. Authorization
packet. Authorization
succeeds
succeeds
Accounting start packet
Accounting start packet
Accounting stop packet
Accounting stop packet
2-5
Protocol Configuration
TACACS
TACACS
Server
Server

Advertisement

Table of Contents
loading

This manual is also suitable for:

S9505S9508S9512

Table of Contents