CHAPTE R
9-1
Cisco IE 3010 Switch Software Configuration Guide
OL-23145-01
9
Configuring Switch-Based Authentication
This chapter describes how to configure switch-based authentication on the IE 3010 switch. This chapter
consists of these sections:
Preventing Unauthorized Access to Your Switch, page 9-1
Protecting Access to Privileged EXEC Commands, page 9-2
Controlling Switch Access with TACACS+, page 9-10
Controlling Switch Access with RADIUS, page 9-18
Controlling Switch Access with Kerberos, page 9-40
Configuring the Switch for Local Authentication and Authorization, page 9-44
Configuring the Switch for Secure Shell, page 9-45
Configuring the Switch for Secure Socket Layer HTTP, page 9-50
Configuring the Switch for Secure Copy Protocol, page 9-57

Preventing Unauthorized Access to Your Switch

You can prevent unauthorized users from reconfiguring your switch and viewing configuration
information. Typically, you want network administrators to have access to your switch while you restrict
access to users who dial from outside the network through an asynchronous por t, connect from outside
the network through a serial port, or connect through a terminal or workstation from withi n the local
network.