Authentication Configuration Guidelines; Configuring Login Authentication - Cisco WS-C2948G-GE-TX Configuration Manual

Catalyst 4500 series switch
Table of Contents

Advertisement

Chapter 30
Configuring Switch Access Using AAA
Table 30-2 Default Authentication Configuration (continued)
Feature
Kerberos login authentication (console and Telnet)
Kerberos enable authentication (console and Telnet)
Kerberos server IP address
Kerberos DES key
Kerberos server auth-port
Kerberos local-realm name
Kerberos credentials forwarding
Kerberos clients mandatory
Kerberos preauthentication

Authentication Configuration Guidelines

This section lists the guidelines for configuring authentication on the switch:

Configuring Login Authentication

The next two sections describe how to configure login authentication on the switch.
Catalyst 4500 Series, Catalyst 2948G, Catalyst 2948G-GE-TX, and Catalyst 2980G Switches Software Configuration Guide—Release 8.2GLX
78-15908-01
Authentication configuration applies both to console and Telnet connection attempts unless you use
the console and telnet keywords to specify the authentication methods to use for each connection
type individually.
If you configure a RADIUS or TACACS+ key on the switch, make sure that you configure an
identical key on the RADIUS or TACACS+ server.
The TACACS+ key must be less than 100 characters.
You must specify a RADIUS or TACACS+ server before enabling RADIUS or TACACS+ on the
switch.
If you configure multiple RADIUS or TACACS+ servers, the first server that you configure is the
primary server, and authentication requests are sent to this server first. You can specify a particular
server as primary by using the primary keyword.
RADIUS and TACACS+ support one privileged mode only (level 1).
Kerberos authentication does not work if TACACS+ is also used as an authentication mechanism.
Before you can enable local user authentication, you must define at least one username.
Local user accounts and passwords must be fewer than 65 characters and can consist of any
alphanumeric characters. Local user accounts must contain at least one alphabetic character.
Configuring Authentication
Default
Disabled
Disabled
None specified
None specified
Port 750
NULL string
Disabled
Not mandatory
Disabled
30-9

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents