H3C SR6600 Fundamentals Configuration Manual page 30

Hide thumbs Also See for SR6600:
Table of Contents

Advertisement

A user is required to input the password (if any) to switch to a higher privilege level for security sake.
The authentication falls into one of the following four categories:
Authentication
mode
Local password
local
authentication
Remote AAA
authentication
scheme
through
HWTACACS or
RADIUS
Performs the local
password
authentication first
local scheme
and then the
remote AAA
authentication
Performs remote
AAA
authentication first
scheme local
and then the local
password
authentication
Follow these steps to set the authentication mode for user privilege level switch:
To do...
Enter system view
Set the authentication mode for
user privilege level switch
Configure the password for user
privilege level switch
Meaning
The switch authenticates a user by using the privilege level switch
password input by the user.
When this mode is applied, you need to set the password for
privilege level switch with the super password command.
The switch sends the username and password for privilege level
switch to the HWTACACS or RADIUS server for remote
authentication.
When this mode is applied, you need to perform the following
configurations:
Configure HWTACACS or RADIUS scheme and reference the
created scheme in the ISP domain. For more information, see
AAA in the Security Configuration Guide.
Create the corresponding user and configure password on the
HWTACACS or RADIUS server.
The switch authenticates a user by using the local password first,
and if no password for privilege level switch is set, for the user
logged in from the console port, the privilege level is switched
directly; for the user logged in from any of the AUX, TTY, or VTY
user interfaces, the AAA authentication is performed.
AAA authentication is performed first, and if the remote
HWTACACS or RADIUS server does not respond or AAA
configuration on the switch is invalid, the local password
authentication is performed.
Use the command...
system-view
super authentication-mode
{ local | scheme } *
super password [ level
user-level ] { simple | cipher }
password
1-19
Description
Remarks
Optional
local by default.
Required if the authentication
mode is set to local (that is, specify
the local keyword when setting the
authentication mode)
By default, no privilege level switch
password is configured.

Advertisement

Table of Contents
loading

Table of Contents