Cisco SCE8000 Configuration Manual page 76

Service control engine
Table of Contents

Advertisement

Configuring the Available Interfaces
Privilege level authorization in the SCE platform is accomplished by the use of an "enable" command
authentication request. When a user requests an authorization for a specified privilege level, by using the
"enable" command, the SCE platform sends an authentication request to the TACACS+ server specifying
the requested privilege level. The SCE platform grants the requested privilege level only after the
TACACS+ server does the following:
Authenticates the " enable " command password
Verifies that the user has sufficient privileges to enter the requested privilege level.
Once the user privilege level has been determined, the user is granted access to a specified set of
commands according to the level granted.
As with login authentication, if the server is unavailable, the next authentication method is attempted, as
explained in
General AAA Fallback and Recovery Mechanism
The SCE platform uses a fall-back mechanism to maintain service availability in case of an error.
The SCE platform uses a fall-back mechanism to maintain service availability in case of an error.
The AAA methods available are:
TACACS+ – AAA is performed by the use of a TACACS+ server, allows authentication,
authorization and accounting.
Local – AAA is performed by the use of a local database, allows authentication and authorization.
Enable – AAA is performed by the use of user configured passwords, allows authentication and
authorization.
None – no authentication\authorization\accounting is performed.
In the current implementation the order of the methods used isn't configurable but the customer can
choose which of the methods are used. The current order is
TACACS+
Local
Enable
None
Note
If the server goes to AAA fault, the SCE platform will not be accessible until one of the AAA methods
is restored. In order to prevent this, it is advisable to use the "none" method as the last AAA method. If
the SCE platform becomes un-accessible, the shell function "AAA_MethodsReset" will allow the user
to delete the current AAA method settings and set the AAA method used to "Enable".
About Configuring TACACS+
The following is a summary of the procedure for configuring TACACS+. All steps are explained in detail
in the remainder of this section.
Configure the remote TACACS+ servers.
1.
Configure the remote servers for the protocols. Keep in mind the following guidelines
Cisco SCE8000 Software Configuration Guide, Rel 3.1.6S
5-8
General AAA Fallback and Recovery Mechanism, page
Configure the encryption key that the server and client will use.
The maximal user privilege level and enable password (password used when executing the
enable command) should be provided.
Chapter 5
Configuring the Management Interface and Security
5-8.
OL-16479-01

Advertisement

Table of Contents
loading

Table of Contents