Authentication And Authorization Process For User Login - Cisco AJ732A - MDS 9134 Fabric Switch Configuration Manual

Cisco nexus 5000 series switch cli software configuration guide, nx-os 4.0(1a)n1 (ol-16597-01, january 2009)
Hide thumbs Also See for AJ732A - Cisco MDS 9134 Fabric Switch:
Table of Contents

Advertisement

Information About AAA
S e n d f e e d b a c k t o n x 5 0 0 0 - d o c f e e d b a c k @ c i s c o . c o m
Table 16-2
AAA Service
Console login authentication
User login authentication
User management session
accounting
Note
For console login authentication, user login authentication, and user management session accounting,
the Nexus 5000 Series switches try each option in the order specified. The local option is the default
method when other configured options fail.

Authentication and Authorization Process for User Login

Figure 16-1
following process occurs:
1.
2.
3.
4.
Cisco Nexus 5000 Series Switch CLI Software Configuration Guide
16-4
AAA Authentication Methods for AAA Services
shows a flowchart of the authentication and authorization process for user login. The
When you log in to the required Nexus 5000 Series switch, you can use the Telnet, SSH, Fabric
Manager or Device Manager, or console login options.
When you have configured the AAA server groups using the server group authentication method,
the Nexus 5000 Series switch sends an authentication request to the first AAA server in the group
as follows:
If the AAA server fails to respond, then the next AAA server is tried and so on until the remote
a.
server responds to the authentication request.
If all AAA servers in the server group fail to respond, then the servers in the next server group
b.
are tried.
If all configured methods fail, then the local database is used for authentication.
c.
If the Nexus 5000 Series switches successfully authenticate you through a remote AAA server, then
the following possibilities apply:
If the AAA server protocol is RADIUS, then user roles specified in the cisco-av-pair attribute
a.
are downloaded with an authentication response.
If the AAA server protocol is TACACS+, then another request is sent to the same server to get
b.
the user roles specified as custom attributes for the shell.
If your username and password are successfully authenticated locally, the Nexus 5000 Series switch
logs you in and assigns you the roles configured in the local database.
AAA Methods
Server groups, local, and none
Server groups, local, and none
Server groups and local
Chapter 16
Configuring AAA
OL-16597-01

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents