Configuring The Authentication Model; How To Set The Switch Authentication Model; Managing The Local Database User Accounts - HP A7533A - Brocade 4Gb SAN Switch Base Administrator's Manual

Hp storageworks fabric os 5.3.x administrator guide (5697-0244, november 2009)
Hide thumbs Also See for A7533A - Brocade 4Gb SAN Switch Base:
Table of Contents

Advertisement

Configuring the authentication model

This section explains how to configure authentication of the switch management channel connections.
Fabric OS 5.3.0 supports use of both the local user database and RADIUS service at the same time. Use
the aaaConfig command to set the authentication model for Fabric OS switch management channel
connection authentication model as shown in
Table 12
Authentication configuration options
aaaConfig Option Description
--localonly
2
--radiusonly
--radiuslocal
--radiuslocalbackup
1.
Fabric OS 5.1.x and earlier aaaConfig --switchdb <on | off> setting.
2.
The console login will never be set to --radiusonly mode for login recovery purposes. When
--radiusonly mode is turned on, console login uses the --radiuslocalbackup mode.

How to set the switch authentication model

1.
Connect to the switch and log in.
2.
Enter this command:
switch:admin> aaaConfig [--localonly | --radiusonly | --radiuslocal |
--radiuslocalbackup]

Managing the local database user accounts

User add, change, and delete operations are subject to the
perform operations on an
must have an ADlist that is a subset of the account that is making the change.
Default setting. Authenticates management
connections against the local database only.
If the password does not match or the user is not
defined, the login fails.
Authenticates management connections against
the RADIUS database(s) only.
If the RADIUS service is not available or the
credentials do not match, the log in fails.
Authenticates management connections against
any RADIUS databases first.
If RADIUS fails for any reason, authenticates
against the local user database.
Authenticates management connections against
any RADIUS databases.
If RADIUS fails because the service is not
available, authenticates against the local user
database.
admin
user
any
,
, or
Table
12.
Equivalent setting in
Fabric OS 5.1.x and later
--radius
Off
On
not supported
On
subset
rule: an admin with ADlist 0- 1 0 cannot
role with an ADlist 1 1-25. The user account being changed
Fabric OS 5.3.0 administrator guide
1
--switchdb
On
Off
not supported
On
65

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents