The following parameters can be set:

 

 

 

Parameter

Description

 

 

Authentication Policy

Use the pull down menu to enable or disable the Authentication Policy on the Switch.

 

Response Timeout (0-255)

This field will set the time the Switch will wait for a response of authentication from the user.The user may set

 

User Attempts (1-255)

a time between 0 and 255 seconds.The default setting is 30 seconds.

 

This command will configure the maximum number of times the Switch will accept authentication attempts.

 

 

Users failing to be authenticated after the set amount of attempts will be denied access to the Switch and will

 

 

be locked out of further authentication attempts. Command line interface users will have to wait 60 seconds

 

 

before another authentication attempt.TELNET and web users will be disconnected from the Switch.The user

 

 

may set the number of attempts from 1 to 255.The default setting is 3.

 

Click Apply to implement changes made.

 

 

Application's Authentication Settings

This window is used to configure switch configuration applications (console,Telnet, SSH, web) for login at the user level and at the administration level (Enable Admin) utilizing a previously configured method list.To view the following window, click Security Management > Access Authentication Control > Application Authentication Settings:

 

 

Figure 7- 6.Application's Authentication Settings window

The following parameters can be set:

 

 

 

Parameter

Description

 

 

Application

Lists the configuration applications on the Switch.The user may configure the Login Method List and

 

 

Enable Method List for authentication for users utilizing the Console (Command Line Interface)

 

Login Method List

application, the Telnet application, SSH and the WEB (HTTP) application.

 

Using the pull down menu, configure an application for normal login on the user level, utilizing a previously

 

 

configured method list.The user may use the default Method List or other Method List configured by the user.

 

Enable Method List

See the Login Method Lists window, in this section, for more information.

 

Using the pull down menu, configure an application for normal login on the user level, utilizing a previously

 

 

configured method list.The user may use the default Method List or other Method List configured by the user.

 

 

See the Enable Method Lists window, in this section, for more information.

 

Click Apply to implement changes made.

 

 

Authentication Server Group Settings

This window will allow users to set up Authentication Server Groups on the Switch.A server group is a technique used to group TACACS/XTACACS/TACACS+/RADIUS server hosts into user-defined categories for authentication using method lists.The user may define the type of server group by protocol or by previously defined server group.The Switch has four built-in Authentication Server Groups that cannot be removed but can be modified. Up to eight (8) authentication server hosts may be added to any particular group.

To view the following window, click Security Management > Access Authentication Control > Authentication Server Group:

Allied Telesyn AT-9724TS High-Density Layer 3 Stackable Gigabit Ethernet Switch

136

Page 137
Image 137
Allied Telesis AT-9724TS Applications Authentication Settings, Authentication Server Group Settings, Login Method List