Table Of Contents - H3C S5500-EI Series Security Configuration Manual

Hide thumbs Also See for S5500-EI Series:
Table of Contents

Advertisement

Contents
Configuring AAA ························································································································································· 1
AAA overview ··································································································································································· 1
RADIUS ······································································································································································ 2
HWTACACS ····························································································································································· 7
Domain-based user management ··························································································································· 9
RADIUS server feature of the switch ···················································································································· 10
AAA for MPLS L3VPNs (available only on the S5500-EI series) ······································································ 11
Protocols and standards ······································································································································· 11
RADIUS attributes ·················································································································································· 12
FIPS compliance ····························································································································································· 15
AAA configuration considerations and task list ·········································································································· 15
Configuring AAA schemes ············································································································································ 16
Configuring local users ········································································································································· 16
Configuring RADIUS schemes ······························································································································ 21
Configuring HWTACACS schemes ····················································································································· 34
Configuring AAA methods for ISP domains ················································································································ 40
Configuration prerequisites ·································································································································· 40
Creating an ISP domain ······································································································································· 41
Configuring ISP domain attributes ······················································································································· 41
Configuring AAA authentication methods for an ISP domain ·········································································· 42
Configuring AAA authorization methods for an ISP domain ··········································································· 44
Configuring AAA accounting methods for an ISP domain ··············································································· 45
Tearing down user connections ···································································································································· 47
Configuring a NAS ID-VLAN binding ·························································································································· 47
Configuring a switch as a RADIUS server ··················································································································· 48
RADIUS server functions configuration task list ·································································································· 48
Configuring a RADIUS user ·································································································································· 48
Specifying a RADIUS client ·································································································································· 49
Displaying and maintaining AAA ································································································································ 49
AAA configuration examples ········································································································································ 50
AAA for Telnet users by an HWTACACS server ······························································································· 50
AAA for Telnet users by separate servers ··········································································································· 51
Authentication/authorization for SSH/Telnet users by a RADIUS server ························································ 52
AAA for portal users by a RADIUS server ·········································································································· 56
AAA for 802.1X users by a RADIUS server ······································································································· 65
Level switching authentication for Telnet users by an HWTACACS server ····················································· 71
RADIUS authentication and authorization for Telnet users by a switch ··························································· 74
Troubleshooting AAA ···················································································································································· 76
Troubleshooting RADIUS ······································································································································· 76
Troubleshooting HWTACACS ······························································································································ 77
802.1X overview ······················································································································································· 78
802.1X architecture ······················································································································································· 78
Controlled/uncontrolled port and port authorization status ······················································································ 78
802.1X-related protocols ·············································································································································· 79
Packet formats ························································································································································ 80
EAP over RADIUS ·················································································································································· 81
Initiating 802.1X authentication ··································································································································· 81
i
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Advertisement

Table of Contents
loading

This manual is also suitable for:

S5500-si series

Table of Contents