Aaa Commands; Configuring Aaa - Enterasys Security Router X-PeditionTM User Manual

Enterasys security router user's guide
Table of Contents

Advertisement

VPN Configuration Overview

AAA Commands

The following XSR AAA commands useful for VPN configuration include:
Configure users and groups with
following sub-commands:
Configure RADIUS, local or PKI databases with the
following sub-commands:
Configure pre-shared keys with

Configuring AAA

Pre-shared keys used in a Peer-to-Peer tunnel are configured using the
The Username is the IP address of a peer
The Password is the pre-shared key
To specify a user and password, enter the following commands:
XSR(config)#aaa user <xxx.xxx.xxx.xxx>
14-26 Configuring the Virtual Private Network
policy
specifies SSH, Telnet, Firewall or VPN service for users
dns-server
wins server
and
and WINS servers to distribute to remote access users and connecting XSRs.
ip pool
associates a globally defined IP address pool (set with
user group. When a remote access user or XSR connects, an IP address is distributed from
this pool. Be aware that if an AAA user is configured to use a static IP address which
belongs to a local IP pool, you must exclude that address from the local pool.
pptp encrypt mppe
configures Microsoft Point-to-Point Encryption on a PPTP link.
ip address
and
group
acct-port
sets the UDP port for accounting requests.
address
specifies the RADIUS server address with either a host name or IP address.
attempts
sets the total of consecutive, unanswered login attempts that must transpire
before the RADIUS method's backup method is used.
auth-port
specifies the UDP port for authentication requests.
enable
activates the method.
group
specifies the default usergroup.
hash enable
initializes the hash algorithm used for RADIUS.
key
sets the shared secret used between the XSR and RADIUS server.
retransmit
specifies the number of RADIUS server retransmissions sent to a server
before timing out.
timeout
sets the interval the XSR waits for the RADIUS server to reply before
retransmitting.
backup
sets the name for the backup RADIUS method.
Caution: We recommend that you do not create more AAA users than permitted by the 1.5 MByte
system limit imposed on the user.dat file. Doing so may render the XSR unstable and require
you to delete the file.
aaa user
and
aaa group
configure the IP addresses of primary and secondary DNS
set the IP address and usergroup assigned to the remote user.
aaa user
and
password
commands as well as the
ip local pool
aaa method
command as well as the
aaa user
) with a
command:

Advertisement

Table of Contents
loading

This manual is also suitable for:

X-pedition xsr

Table of Contents