Contents
ix
Cisco IE 3010 Switch Software Configuration Guide
OL-23145-01
Configuring RADIUS 9-27
Default RADIUS Configuration 9-27
Identifying the RADIUS Server Host 9-28
Configuring RADIUS Login Authentication 9-30
Defining AAA Server Groups 9-32
Configuring RADIUS Authorization for User Privileged Access and Network Services 9-34
Starting RADIUS Accounting 9-35
Establishing a Session with a Router if the AAA Server is Unreachable 9-36
Configuring Settings for All RADIUS Servers 9-36
Configuring the Switch to Use Vendor-Specific RADIUS Attributes 9-36
Configuring the Switch for Vendor-Proprie tary RADIUS Server Communication 9-38
Configuring CoA on the Switch 9-39
Monitoring and Troubleshooting CoA Functionality 9-40
Configuring RADIUS Server Load Balancing 9-40
Displaying the RADIUS Configuration 9-40
Controlling Switch Access with Kerberos 9-40
Understanding Kerberos 9-41
Kerberos Operation 9-43
Authenticating to a Boundary Switch 9-43
Obtaining a TGT from a KDC 9-43
Authenticating to Network Services 9-44
Configuring Kerberos 9-44
Configuring the Switch for Local Authentication and Authorization 9-44
Configuring the Switch for Secure Shell 9-45
Understanding SSH 9-46
SSH Servers, Integrated Clients, and Su pported Versions 9-46
Limitations 9-46
Configuring SSH 9-47
Configuration Guidelines 9-47
Setting Up the Switch to Run SSH 9-47
Configuring the SSH Server 9-48
Displaying the SSH Configuration and Status 9-49
Configuring the Switch for Secure Socket Layer HTTP 9-50
Understanding Secure HTTP Servers and Clients 9-51
Certificate Authority Trustpoints 9-51
CipherSuites 9-52
Configuring Secure HTTP Servers and Clients 9-53
Default SSL Configuration 9-53
SSL Configuration Guidelines 9-53