Criteria For Failure Of Authentication Methods - HP ProCurve Secure 7000dl Series Basic Management And Configuration Manual

Secure router procurve 7000dl series
Hide thumbs Also See for ProCurve Secure 7000dl Series:
Table of Contents

Advertisement

N o t e
For example, when you configure a named list for user authentication, you
may want to call this list UserLogin. You may also decide to use the following
authentication methods:
enable password
line password
local user database
In this case, you would enter:
ProCurve(config)# aaa authentication login UserLogin enable line local
If you select the enable password as an authentication method for an access
method that requires a username, the username is, by default, $enab15$.
You can change this username for RADIUS servers when you enter the
radius-server command, as explained in "Define the RADIUS Server" on
page 2-27.
If no enable password has been defined, the AAA subsystem moves to the line
username and password. If no username and password have been defined for
the line, the AAA subsystem moves to the local user database and tries to
match the username and password that the user enters to a username and
password in that database.

Criteria for Failure of Authentication Methods

The AAA subsystem skips an authentication method if the method itself fails.
However, if a user fails to enter the correct password, that user is denied
access to the router. The user failed in his or her attempt to authenticate; the
authentication method did not fail.
The ProCurve Secure Router uses the following criteria to determine if an
authentication method failed:
Line and enable passwords fail if no line or enable passwords are configured.
RADIUS or TACACS+ servers fail if the ProCurve Secure Router tries to
communicate with them but they do not respond.
The local user list fails if the given user is not listed in the database.
For example, if you configure the authentication methods with RADIUS as the
first option and the RADIUS server goes down, the AAA subsystem tries the
next authentication method you configured. If you listed the local user list
after the RADIUS server, the AAA subsystem will use that authentication
method next.
Controlling Management Access to the ProCurve Secure Router
Using the AAA Subsystem to Control Management Access
2-19

Advertisement

Table of Contents
loading

This manual is also suitable for:

Procurve 7102dl seriesProcurve 7103dl series

Table of Contents