Advantages Of Using The Aaa Subsystem; Enabling The Aaa Subsystem - HP ProCurve Secure 7000dl Series Basic Management And Configuration Manual

Secure router procurve 7000dl series
Hide thumbs Also See for ProCurve Secure 7000dl Series:
Table of Contents

Advertisement

Advantages of Using the AAA Subsystem

The AAA subsystem provides more flexibility than simple password-based
authentication. If you enable the AAA subsystem, you can configure a list of
authentication methods for the enable mode and for each access method. For
example, you could configure a list of authentication methods for Telnet
access or for SSH access. The authentication methods include:
the Telnet password
the enable mode password
the local userlist
a RADIUS server
a TACACS+ server
You configure the list of authentication methods in the order in which you
want them used. Then, if one method fails, the next method is used. (For
information about what constitutes a failure, see "Criteria for Failure of
Authentication Methods" on page 2-19.)
The AAA subsystem allows you to use a standard authentication method
across your entire network. If you are using a RADIUS server or a TACACS+
server to authenticate network services and applications, you can use this
same server to authenticate management access to the ProCurve Secure
Router.
In addition to controlling management access, the AAA subsystem can be used
to authenticate VPN users when Xauth is configured. (For more information
about Xauth, see the ProCurve Secure Router Advanced Management and
Configuration Guide, Chapter 8: Virtual Private Networks.)
The AAA subsystem also strengthens your WAN security by supporting autho-
rization and accounting for management access to the ProCurve Secure
Router. Enforced through a TACACS+ server, authorization and accounting
go beyond password authentication to ensure that only authorized users
perform management functions and to provide a record of the configuration
commands entered.

Enabling the AAA Subsystem

By default, the AAA subsystem is disabled. To enable it, move to the global
configuration mode context and enter:
ProCurve(config)# aaa on
Controlling Management Access to the ProCurve Secure Router
Using the AAA Subsystem to Control Management Access
2-15

Advertisement

Table of Contents
loading

This manual is also suitable for:

Procurve 7102dl seriesProcurve 7103dl series

Table of Contents