Contents
ix
Catalyst 3560 Switch Software Configuration Guide
OL-8553-06
Disabling Password Recovery 9-5
Setting a Telnet Password for a Terminal Line 9-6
Configuring Username and Password Pairs 9-6
Configuring Multiple Privilege Levels 9-7
Setting the Privilege Level for a Command 9-8
Changing the Default Privilege Level for Lines 9-9
Logging into and Exiting a Privilege Level 9-9
Controlling Switch Access with TACACS+ 9-10
Understanding TACACS+ 9-10
TACACS+ Operation 9-12
Configuring TACACS+ 9-12
Default TACACS+ Configuration 9-13
Identifying the TACACS+ Server Host and Setting the Authentication Key 9-13
Configuring TACACS+ Login Authentication 9-14
Configuring TACACS+ Authorization for Privileged EXEC Access and Network Services 9-16
Starting TACACS+ Accounting 9-17
Displaying the TACACS+ Configuration 9-17
Controlling Switch Access with RADIUS 9-17
Understanding RADIUS 9-18
RADIUS Operation 9-19
Configuring RADIUS 9-19
Default RADIUS Configuration 9-20
Identifying the RADIUS Server Host 9-20
Configuring RADIUS Login Authentication 9-23
Defining AAA Server Groups 9-25
Configuring RADIUS Authorization for User Privileged Access and Network Services 9-27
Starting RADIUS Accounting 9-28
Configuring Settings for All RADIUS Servers 9-29
Configuring the Switch to Use Vendor-Specific RADIUS Attributes 9-29
Configuring the Switch for Vendor-Proprietary RADIUS Server Communication 9-31
Configuring RADIUS Server Load Balancing 9-31
Displaying the RADIUS Configuration 9-32
Controlling Switch Access with Kerberos 9-32
Understanding Kerberos 9-32
Kerberos Operation 9-34
Authenticating to a Boundary Switch 9-35
Obtaining a TGT from a KDC 9-35
Authenticating to Network Services 9-35
Configuring Kerberos 9-35