Configuring Kerberos Authentication - Cisco WS-C2948G-GE-TX Configuration Manual

Catalyst 4500 series switch
Table of Contents

Advertisement

Configuring Authentication
----------------------------- -------
172.20.52.3
Console> (enable)
Disabling RADIUS Authentication
If you disable RADIUS authentication with both TACACS+ and local authentication disabled, local
authentication is reenabled automatically.
To disable RADIUS authentication, perform this task in privileged mode:
Task
Step 1
Disable RADIUS authentication for login mode.
Step 2
Disable RADIUS authentication for enable mode. set authentication enable radius disable [all |
Step 3
Verify the RADIUS configuration.
This example shows how to disable RADIUS authentication:
Console> (enable) set authentication login radius disable
radius login authentication set to disable for console and telnet session.
Console> (enable) set authentication enable radius disable
radius enable authentication set to disable for console and telnet session.
Console> (enable) show authentication
Login Authentication:
---------------------
tacacs
radius
local
Enable Authentication: Console Session
---------------------- ----------------- ----------------
tacacs
radius
local
Console> (enable)

Configuring Kerberos Authentication

Before you can use Kerberos as an authentication method on the switch, you need to configure the
Kerberos server. You will need to create a database for the KDC and add the switch to the database.
To configure the Kerberos server, follow these steps:
Step 1
Before you can enter the switch in the Kerberos server's key table, you must create the database that the
KDC will use. In the following example, a database called CISCO.EDU is created:
/usr/local/sbin/kdb5_util create -r CISCO.EDU -s
Catalyst 4500 Series, Catalyst 2948G, Catalyst 2948G-GE-TX, and Catalyst 2980G Switches Software Configuration Guide—Release 8.2GLX
30-30
------------
primary
1812
Command
set authentication login radius disable [all |
console | http | telnet]
console | http | telnet]
show radius
show authentication
Console Session
Telnet Session
----------------
----------------
disabled
disabled
disabled
disabled
enabled(primary)
enabled(primary)
Telnet Session
disabled
disabled
disabled
disabled
enabled(primary)
enabled(primary)
Chapter 30
Configuring Switch Access Using AAA
78-15908-01

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents