Alaxala AX2200S Series Configuration Manual page 111

Table of Contents

Advertisement

Figure 8-7 Correlation diagram of authentication method configuration
You can specify these authentication methods singly or in combination, which allows the
user to be authenticated by the next specified method if authentication by the first specified
method fails. When multiple authentication methods are specified, the
authentication login end-by-reject
of the authentication service performed when the first-specified authentication method fails.
You cannot simultaneously specify both
authentication) and
figure, because both methods are treated as the RADIUS authentication service. Use
either of them in combination with local password authentication.
(a) When end-by-reject is not set
The following explains how an authentication service is selected when end-by-reject is not
set. If authentication fails when using the first specified method when end-by-reject is not
set, authentication can be performed using the next specified method regardless of the
reason of failure. The figure below shows an example of the authentication sequence. In
this example, RADIUS authentication and local password authentication are specified in
that order as authentication methods. The RADIUS server authentication is denied, but
local password authentication succeeds.
Figure 8-8 Sequence of authentication (without end-by-reject specified)
In this figure, the user accesses the Switch via Telnet from a remote terminal, and the
Switch requests the RADIUS server to perform authentication. If RADIUS server
authentication fails because the RADIUS server denied the request, the Switch performs
authentication using local password authentication. At this point, authentication is
successful and the user is able to log in to the Switch.
(b) When end-by-reject is set
The following explains how an authentication service is selected when end-by-reject is set.
configuration command can change the behavior
group radius
group
group-name (RADIUS server group authentication) in the above
8 Login Security and RADIUS
aaa
(general-use RADIUS server
89

Advertisement

Table of Contents
loading

This manual is also suitable for:

Ax1250s seriesAx1240s series

Table of Contents