Configuring Server Groups; Local Aaa; Authentication And Authorization Process - Cisco DS-C9216I-K9 Configuration Manual

Switch guide
Table of Contents

Advertisement

Chapter 18
Configuring Switch Security

Configuring Server Groups

You can specify one or more remote AAA servers to authenticate users using server groups. All members
of a group must belong to the same protocol: either RADIUS or TACACS+. The servers are tried in the
same order in which you configure them.
You can configure these server groups at any time but they only take effect when you apply them to a
AAA service. From Fabric Manager, choose Switches > Security > AAA > Server Groups.
You can specify one or more remote AAA servers to authenticate users using server groups.

Local AAA

The system maintains the user name and password locally and stores the password information in
encrypted form. You are authenticated based on the locally stored user information.

Authentication and Authorization Process

Authentication is the process of verifying the identity of the person managing the switch. This identity
verification is based on the user ID and password combination provided by the person trying to manage
the switch. The Cisco MDS 9000 Family switches allow you to perform local authentication (using the
lookup database) or remote authentication (using one or more RADIUS servers or TACACS+ servers).
The following steps explain the authorization and authentication process. shows a flow chart of the
process.
OL-7753-01
Cisco MDS 9000 Fabric Manager Switch Configuration Guide
Configuring Server Groups
18-9

Advertisement

Table of Contents
loading

Table of Contents