Chapter 3: Operations

27

 

 

You must specify the server’s IP address, the UDP port to be used and a “secret” to be used. You must also specify a user-rights attribute value that matches a value in the RADIUS server’s dictionary.

You may also use this command to delete a RADIUS server definition.

SERVER RADIUS PRIMARYSECONDARY DELETE

For more information, see Server RADIUS command on page 55.

2.Issue a Server Security command, using the Authentication parameter to specify the authenti- cation method. Use the Encrypt parameter to enable plain text Telnet connections, SSH con- nections or both.

SERVER SECURITY AUTHENTICATION=<auth> ENCRYPT=<conns>

When SSH session access is enabled, you must specify an authentication method other than None.

3.You are prompted to save the information. Enter Y to confirm or N to cancel.

To enable or disable authentication of serial CLI port sessions:

Issue a Server CLI command, using the Auth parameter to enable/disable serial CLI port authentication and the Preempt parameter to specify the preemption level.

To clear stored DSView software authentication credentials:

Issue a Server Security command, using the DSClear parameter. This clears any stored credentials used by the DSView software.

To display authentication configuration information:

1.Issue a Show Server Security command.

SHOW SERVER SECURITY

The display includes the current CPS appliance authentication settings that were configured with the Server Security command. If SSH access has been enabled, the display indicates SSH2. Regardless of whether SSH is enabled, the display includes the authentication method specified with the Server SSH command.

2.To display CPS RADIUS settings that were configured with the Server RADIUS command, issue a Show Server RADIUS command.

SHOW SERVER RADIUS

For more information, see Server Security command on page 57, Show Server Security command on page 66, Show Server RADIUS command on page 66 and Connecting to devices using SSH on page 16.

Using security lock-out

When the security lock-out feature is enabled, a user will be locked-out after five consecutive authentication failures. A successful authentication will reset the counter to zero. You may