Customizing Aaa With "Globs" And Groups; Setting User Passwords - D-Link DWS-1008 - AirPremier MobileLAN Switch Product Manual

8 port 10/100 wireless switch with power over ethernet
Hide thumbs Also See for DWS-1008 - AirPremier MobileLAN Switch:
Table of Contents

Advertisement

Customizing AAA with "Globs" and Groups

"Globbing" lets you classify users by username or media access control (MAC) address for different
AAA treatments. A user glob is a string, possibly containing wildcards, for matching AAA and IEEE
802.1X authentication methods to a user or set of users. The switch supports the following wildcard
characters for user globs:
• Single asterisk (*) matches the characters in a username up to but not including a separator
character, which can be an at (@) sign or a period (.).
• Double asterisk (**) matches all usernames.
In a similar fashion, MAC address globs match authentication methods to a MAC address or set of MAC
addresses. For details, see "User Globs, MAC Address Globs, and VLAN Globs" on page 12.
A user group is a named collection of users or MAC addresses sharing a common authorization policy.
For example, you might group all users on the first floor of building 17 into the group bldg-17-1st-floor,
or group all users in the IT group into the group infotech-people. Individual user entries override group
entries if they both configure the same attribute.
Like usernames, passwords are case-sensitive. To make passwords secure, make sure they contain
uppercase and lowercase letters and numbers. D-Link recommends that all users create passwords
that are memorable to themselves, difficult for others to guess, and not subject to a dictionary attack.
User passwords are automatically encrypted when entered in the local database. However, the encryption
is not strong. It is designed only to discourage someone looking over your shoulder from memorizing
your password as you display the configuration. To maintain security, MSS displays only the encrypted
form of the password in show commands.
Note: Although MSS allows you to configure a user password for the special "last-resort" guest
user, the password has no effect. Last-resort users can never access a DWS-1008 switch in
administrative mode and never require a password.
D-Link DWS-1008 User Manual

Setting User Passwords

0

Advertisement

Table of Contents
loading

Table of Contents