AAA, RADIUS, and HWTACACS Protocol Configuration Examples 239

Figure 58 Configuring Remote RADIUS Authentication for Telnet Users

Authentication Servers

(IP address: 10.110.91.164)

Internet

Telnet user

Switch

 

1Add a Telnet user.

For details about configuring FTP and Telnet users, see “Configuring the User Interface” on page 20.

2Configure the remote authentication mode for the Telnet user, in this example, the scheme mode.

[SW7750-ui-vty0-4]authentication-mode scheme

3Configure the domain.

[SW7750]domain cams

[SW7750-isp-cams]quit

4Configure RADIUS scheme.

[SW7750]radius scheme cams [SW7750-radius-cams]primary authentication 10.110.91.146 1812

[SW7750-radius-cams]key authentication expert

[SW7750-radius-cams]server-type 3com

[SW7750-radius-cams]user-name-format without-domain

5Configure the association between domain and RADIUS.

[SW7750-radius-cams]quit

[SW7750]domain cams

[SW7750-isp-cams]radius-scheme cams

Configuring FTP/Telnet Local RADIUS authentication of Telnet/FTP users is similar to remote RADIUS User Authentication at authentication. But you should modify the server IP address to 127.0.0.1,

the Local RADIUS Server authentication password to 3Com, the UDP port number of the authentication server to 1645.

For details about local RADIUS authentication of Telnet/FTP users, see “Configuring a Local RADIUS Server Group”on page 228.

Configuring the Configure the switch to use a TACACS server to provide AAA services to login FTP/Telnet User users (see the following figure).

Authentication at a

Remote TACACS Server Connect the switch to one TACACS server (providing the services of authentication and authorization) with the IP address 10.110.91.164. On the

Page 239
Image 239
3Com 10014298 manual Configure the domain, Configure Radius scheme, Configure the association between domain and Radius