Switch Aaa Functionalities; Authentication; Authorization; Accounting - Cisco MDS 9000 Series Configuration Manual

Security
Hide thumbs Also See for MDS 9000 Series:
Table of Contents

Advertisement

Configuring Security Features on an External AAA Server

Switch AAA Functionalities

Using the CLI or Fabric Manager, or an SNMP application, you can configure AAA switch functionalities
on any switch in the Cisco MDS 9000 Family.
This section includes the following topics:

Authentication

Authentication is the process of verifying the identity of the person or device accessing the switch. This identity
verification is based on the user ID and password combination provided by the entity trying to access the
switch. Cisco MDS 9000 Family switches allow you to perform local authentication (using the local lookup
database) or remote authentication (using one or more RADIUS or TACACS+ servers).
Note
Fabric Manager does not support AAA passwords with trailing white space, for example "passwordA."

Authorization

The following authorization roles exist in all Cisco MDS switches:
• Network operator (network-operator)—Has permission to view the configuration only. The operator
• Network administrator (network-admin)— Has permission to execute all commands and make
• Default-role—Has permission to use the GUI (Fabric Manager and Device Manager). This access is
These roles cannot be changed or deleted. You can create additional roles and configure the following options:
• Configure role-based authorization by assigning user roles locally or using remote AAA servers.
• Configure user profiles on a remote AAA server to contain role information. This role information is
Note
If a user belongs only to one of the newly created roles and that role is subsequently deleted, then the user
immediately defaults to the network-operator role.

Accounting

The accounting feature tracks and maintains a log of every management configuration used to access the
switch. This information can be used to generate reports for troubleshooting and auditing purposes. Accounting
logs can be stored locally or sent to remote AAA servers.
cannot make any configuration changes.
configuration changes. The administrator can also create and customize up to 64 additional roles.
automatically granted to all users for accessing the GUI.
automatically downloaded and used when the user is authenticated through the remote AAA server.
Cisco MDS 9000 Series Security Configuration Guide, Release 8.x

Switch AAA Functionalities

31

Advertisement

Table of Contents
loading

Table of Contents