176CHAPTER 18: AAA CONFIGURATION GUIDE
Complete Configuration | # |
| |
| hwtacacs scheme hwtac |
| primary authentication 10.110.91.164 49 |
| primary authorization 10.110.91.164 49 |
| key authentication expert |
| key authorization expert |
| |
| quit |
| # |
| domain hwtacacs |
| scheme |
| accounting optional |
Precautions | The above describes only the configuration of the HWTACACS scheme on the |
| switch. The configuration of Telnet users on the HWTACACS server is omitted. |
|
|
Configuring EAD | Endpoint Admission Defense (EAD) is an attack defense solution. By controlling |
| access of terminals, it enhances the active defense capability of network endpoints |
| and prevents viruses and worms from spreading on the network, thus securing the |
| entire network. |
| With the cooperation of the switch, AAA sever, security policy server and security |
| client, EAD is able to evaluate the security compliance of network endpoints and |
| dynamically control their access rights. |
| With EAD, a switch verifies the validity of the session control packets it receives |
| according to the source IP addresses of the packets: |
| It regards only packets from the authentication and security policy servers valid. |
| It assigns ACLs according to session control packets, thus controlling the access |
| rights of users dynamically. |
Network Diagram | Figure 47 Network diagram for configuring EAD |
| Authentication servers |
| 10.110.91.164/16 |
Eth1/0/1
User
Internet
Security policy servers | Virus patch servers |
10.110.91.166/1610.110.91.168/16