Management Access Security; Authenticating Users Using Radius Or Tacacs; Radius Client - Extreme Networks ExtremeWare 7.2e Installation And User Manual

Software version 7.2e
Table of Contents

Advertisement

Security
flood of response packets is not mistaken as the attack. To configure a trusted port, use the following
command:
configure cpu-dos-protect trusted-ports <port number>
For example, to make ports 5 and 7 trusted ports, you would issue this command:
config cpu-dos-protect trusted-ports 5, 7
To make all ports trusted, or in other words, to disable DoS protection, use the following command:
disable cpu-dos-protect

Management Access Security

Management access security features control access to the management functions available on the
switch. These features help insure that any configuration changes to the switch can only be done by
authorized users. In this category are the following features:

Authenticating Users Using RADIUS or TACACS+

Secure Shell 2 (SSH2)
Authenticating Users Using RADIUS or TACACS+
ExtremeWare provides two methods to authenticate users who login to the switch:

• RADIUS client

• TACACS+
RADIUS Client
Remote Authentication Dial In User Service (RADIUS, RFC 2138) is a mechanism for authenticating and
centrally administrating access to network nodes. The ExtremeWare RADIUS client implementation
allows authentication for Telnet, Vista, or console access to the switch.
NOTE
You cannot configure RADIUS and TACACS+ at the same time.
You can define a primary and secondary RADIUS server for the switch to contact. When a user
attempts to login using Telnet, http, or the console, the request is relayed to the primary RADIUS server,
and then to the secondary RADIUS server, if the primary does not respond. If the RADIUS client is
enabled, but access to the RADIUS primary and secondary server fails, the switch uses its local database
for authentication.
The privileges assigned to the user (admin versus nonadmin) at the RADIUS server take precedence
over the configuration in the local switch database.
To configure the RADIUS servers, use the following command:
170
ExtremeWare 7.2e Installation and User Guide

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents