How To Add A Radius Server To The Switch Configuration; How To Enable And Disable A Radius Server; How To Delete A Radius Server From The Configuration - HP A7533A - Brocade 4Gb SAN Switch Base Administrator's Manual

Hp storageworks fabric os 5.3.x administrator guide (5697-0244, november 2009)
Hide thumbs Also See for A7533A - Brocade 4Gb SAN Switch Base:
Table of Contents

Advertisement

How to add a RADIUS server to the switch configuration

1.
Connect to the switch and log in as admin.
2.
Enter this command:
switch:admin> aaaConfig --add
[-a pap | chap]
server
-p port
-s secret
-t timeout
-a[pap|chap]peap
-mschapv2
At least one RADIUS server must be configured before you can enable RADIUS service.
If no RADIUS configuration exists, turning it on triggers an error message. When the command succeeds,
the event log indicates that the configuration is enabled or disabled.
CAUTION:
When the RADIUS authentication mode is set to radiuslocal, you cannot downgrade
Fabric OS to any version lower than v5.2.x: previous versions do not support the radiuslocal mode.

How to enable and disable a RADIUS server

1.
Connect to the switch and log in as admin.
2.
Enter this command to enable RADIUS + local:
switch:admin> aaaconfig --radiuslocal
Local is used if the user authentication fails on the RADIUS server. Or to enable RADIUS + localbackup:
switch:admin> aaaconfig --radiuslocalbackup
Local is used if the RADIUS servers are not accessible.

How to delete a RADIUS server from the configuration

1.
Connect to the switch and log in as admin.
2.
Enter this command:
switch:admin> aaaConfig --remove
server
At the prompt, enter y to complete the command.
3.
When the command succeeds, the event log indicates that the server is removed.
82
Managing user accounts
server
Enter either a server name or IP address. Avoid duplicating server listings
(that is, listing the same server once by name and again by IP address).
Up to five servers can be added to the configuration.
Optionally, enter a server port. The default is port 1812.
Optionally, enter a shared secret. The default is "sharedsecret". Secrets can
be from 8 to 40 alphanumeric characters long. Make sure that the secret
matches that configured on the server.
Optionally, enter the length of time (in seconds) that the server has to
respond before the next server is contacted. The default is three seconds.
Time-out values can range from 1 to 30 seconds.
Specify PAP, CHAP or PEAP as authentication protocol. Use
peap-mschapv2 to provide encrypted authentication channel between
switch and server.
server
Enter either the name or IP address of the server to be removed.
port
secret
[-p
] [-s
] [-t
| all
timeout
]

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents