Cisco 500 Series Administration Manual page 453

Stackable managed
Hide thumbs Also See for 500 Series:
Table of Contents

Advertisement

21
STEP 1
STEP 2
STEP 3
STEP 4
STEP 5
451
If authorization is enabled, and an authentication method fails or the user has
insufficient privilege level, the user is denied access to the device. In other words,
if authentication fails for an authentication method, the device stops the
authentication attempt; it does not continue and does not attempt to use the next
authentication method.
Similarly, if authorization is not enabled, and authentication fails for a method, the
device stops the authentication attempt.
To define authentication methods for an access method:
Click Security > Management Access Authentication.
Enter the Application (type) of the management access method.
Select Authorization to enable both authentication and authorization of the user
by the list of methods described below. If the field is not selected, only
authentication is performed. If Authorization is enabled, the read/write privileges
of users are checked. This privilege level is set in the User Accounts page.
Use the arrows to move the authorization/authentication method between the
Optional Methods column and the Selected Methods column. Methods are
attempted in the order that they appear.
Use the arrows to move the authentication method between the Optional Methods
column and the Selected Methods column. The first method selected is the first
method that is used.
RADIUS—User is authorized/authenticated on a RADIUS server. You must
have configured one or more RADIUS servers. For the RADIUS server to
grant access to the web-based configuration utility, the RADIUS server must
return cisco-avpair = shell:priv-lvl=15.
TACACS+—User authorized/authenticated on the TACACS+ server. You
must have configured one or more TACACS+ servers.
None—User is allowed to access the device without authorization/
authentication.
Local—Username and password are checked against the data stored on the
local device. These username and password pairs are defined in the User
Accounts page.
The Local or None authentication method must always be
NOTE
selected last. All authentication methods selected after Local or None
are ignored.
Cisco 500 Series Stackable Managed Switch Administration Guide
Management Access Authentication
Security

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents