Accton Technology VS4512DC manual Configuring Local/Remote Logon Authentication

Models: VS4512DC VS4512

1 334
Download 334 pages 13.79 Kb
Page 55
Image 55
RADIUS/
TACACS+ server
1. Client attempts management access.
2. Switch contacts authentication server.
3. Authentication server challenges client.
4. Client responds with proper password or key.
5. Authentication server approves access.
6. Switch grants management access.
Web
Telnet
console

User Authentication.

CLI – Assign a user name to access-level 15 (i.e., administrator), then specify the password.

Console(config)#username bob access-level 15

4-24

Console(config)#username bob password 0 smith

Console(config)#

Configuring Local/Remote Logon Authentication

Use the Authentication Settings menu to restrict management access based on specified user names and passwords. You can manually configure access rights on the switch, or you can use a remote access authentication server based on RADIUS or TACACS+ protocols.

Remote Authentication Dial-in

User Service (RADIUS) and

Terminal Access Controller Access Control System Plus (TACACS+) are logon authentication protocols

that use software running on a

central server to control access to RADIUS-aware or TACACS

-aware devices on the network. An authentication server contains a database of multiple user name/ password pairs with associated

privilege levels for each user that requires management access to the switch.

RADIUS uses UDP while TACACS+ uses TCP. UDP only offers best effort delivery, while TCP offers a connection-oriented transport. Also, note that RADIUS encrypts only the password in the access-request packet from the client to the server, while TACACS+ encrypts the entire body of the packet.

Command Usage

By default, management access is always checked against the authentication database stored on the local switch. If a remote authentication server is used, you must specify the authentication sequence and the corresponding parameters for the remote authentication protocol. Local and remote logon authentication control management access via the console port, web browser, or Telnet.

RADIUS and TACACS+ logon authentication assign a specific privilege level for each user name/password pair. The user name, password, and privilege level must be configured on the authentication server.

You can specify up to three authentication methods for any user to indicate the authentication sequence. For example, if you select (1) RADIUS, (2) TACACS and (3) Local, the user name and password on the RADIUS server is verified first. If the RADIUS server is not available, then authentication is attempted using the TACACS+ server, and finally the local user name and password is checked.

3-25

Page 55
Image 55
Accton Technology VS4512DC manual Configuring Local/Remote Logon Authentication

VS4512DC, VS4512 specifications

Accton Technology is renowned for its innovative networking solutions and has made significant strides in the realm of networking devices with its VS4512 and VS4512DC models. These devices cater primarily to the advanced needs of enterprise and data center environments, providing robust features and cutting-edge technologies that enhance network performance and reliability.

The Accton VS4512 is a high-performance Layer 2+ switch designed for top-of-rack applications in data centers. It boasts a compact 1U design, making it highly efficient for space-constrained environments. One of its standout features is the support for Ethernet Flow Control, which significantly reduces data loss during peak traffic loads. This is essential for businesses that rely on real-time data processing and streaming.

In terms of scalability, the VS4512 supports up to 48 Gigabit Ethernet ports, which can be expanded using four 10 Gigabit SFP+ uplink ports. This flexibility allows enterprises to customize their network architecture to meet their growing demands, whether they are scaling up for more users or enhancing service capabilities.

The VS4512DC, on the other hand, is the DC version tailored for data centers. It offers similar features as the VS4512 but includes enhancements for power efficiency and redundancy, ensuring that operations can continue smoothly even in power outage scenarios. The VS4512DC features dual power supplies and advanced thermal management, allowing for improved heat dissipation and lower operational costs.

Both models support advanced Layer 3 routing capabilities, enabling efficient traffic management across complex networks. They also incorporate features like VLAN segmentation and link aggregation, which facilitate better bandwidth utilization and improved network security.

Security is another cornerstone of these switches, with features such as DHCP snooping, port security, and storm control to mitigate risks associated with unauthorized access and network congestion.

In summary, the Accton Technology VS4512 and VS4512DC switches represent significant advancements in networking technology, equipped with a comprehensive set of features tailored for modern enterprise needs. With their scalability, robust performance, and focus on security, these switches are positioned to meet the challenges of today's fast-paced digital environments, making them a preferred choice for organizations aiming to enhance their network infrastructure.