Authentication; Authorization; Accounting; Remote Authentication By Aaa Servers - Cisco DS-C9216I-K9 Configuration Manual

Switch guide
Table of Contents

Advertisement

Chapter 18
Configuring Switch Security

Authentication

Authentication is the process of verifying the identity of the person managing the switch. This identity
verification is based on the user ID and password combination provided by the person trying to manage
the switch. Cisco MDS 9000 Family switches allow you to perform local authentication (using the
lookup database) or remote authentication (using one or more RADIUS or TACACS+ servers).

Authorization

By default, two roles exist in all switches:
The two default roles cannot be changed or deleted. You can create additional roles and configure the
following options:

Accounting

Accounting refers to the log that is kept for each management session in a switch. This information may
be used to generate reports for troubleshooting purposes and user accountability. Accounting can be
implemented locally and remotely.

Remote Authentication by AAA Servers

AAA authentication provides the following advantages over local database authentication:

Remote Authentication Guidelines

When you prefer using remote C servers, follow these guidelines:
OL-7753-01
Network operator (network-operator)—Has permission to view the configuration only. The operator
cannot make any configuration changes.
Network administrator (network-admin)—Has permission to execute all commands and make
configuration changes. The administrator can also create and customize up to 64 additional roles.
Assign user roles either locally or using remote AAA servers.
Configure user profiles on a remote AAA server to contain role information. This role information
is automatically downloaded and used when that user is authenticated through remote AAA server.
Requires only one password to be shared between the switch and the AAA servers.
Easier to manage user password lists for each switch in the fabric.
AAA servers are deployed widely across enterprises and can be easily adopted.
A minimum of one AAA server should be IP reachable.
If all configured AAA servers are not reachable, the policy configured on the switch determines the
authentication method.
Cisco MDS 9000 Fabric Manager Switch Configuration Guide
Switch AAA Functionalities
18-3

Advertisement

Table of Contents
loading

Table of Contents