AAA Settings tab 12

5.Enter the password for the Management application service account configured on the AD server in the Password and Confirm Password fields.

6.Enter the Kerberos SPN in the Kerberos Service Principal Name field.

The SPN name uses the following syntax: <Service_Name>/<Hostname>, where hostname is the Management application server’s host name with domain name. For example: NetworkManagementSPN/DCM-VNext-65.JCB.COM

7.Test the established active connection with the server by clicking Test.

The Test Authentication dialog box displays. Test performs the following functions and verifications:

Obtains the Kerberos Ticket Granting Ticket (TGT) of the currently logged in user from Windows cached credentials.

Sends the TGT to the AD server to which the Management application server is connected and requests the session ticket for the SPN configured on AD server.

Kerberos encryptsthe session ticket with the credentials of the AD server user account mapped to this SPN.

Logs on to the AD of the Management application server using the AD server single-sign-on (SSO) service account.

Verifies the service ticket by decrypting it using AD server SSO service account credentials.

8.Click Apply to save the configuration.

To display the authentication audit trail, refer to “Displaying the client authentication audit trail” on page 391.

9.Click Close to close the Server Management Console.

Configuring switch authentication

Switch authentication enables you to authenticate a user account against the switch database and the Management application server. You can configure up to three switches and specify the fall back order if one or more of the switches is not available.

NOTE

Switch authentication is only supported on Fabric OS devices.

To configure switch authentication, complete the following steps.

1.Select the AAA Settings tab.

2.For Primary Authentication, select Switch.

3.Click Add.

4.Enter the switch IP address and click OK. You can add up to three switches.

5.Select a switch and click the Up or Down button to set the fall back order.

6.Select a switch and click Delete to remove a switch from the list.

7.Set secondary authentication by selecting one of the following options from the Secondary Authentication list:

Brocade Network Advisor IP User Manual

389

53-1003056-01

 

Page 441
Image 441
Brocade Communications Systems IP250 Configuring switch authentication, For Primary Authentication, select Switch