Contents
xii
Cisco IE 2000 Switch Software Configuration Guide
OL-25866-01
TACACS+ 12-5
TACACS+ Operation 12-6
Default TACACS+ Configuration 12-7
TACACS+ Server Host and the Authentication Key 12-7
TACACS+ Login Authentication 12-7
TACACS+ Authorization for Privileged EXEC Access and Network Services 12-7
TACACS+ Accounting 12-8
Switch Access with RADIUS 12-8
RADIUS 12-8
RADIUS Operation 12-9
Default RADIUS Configuration 12-10
RADIUS Change of Authorization 12-10
CoA Request Commands 12-12
RADIUS Server Host 12-14
RADIUS Login Authentication 12-15
Radius Method List 12-15
AAA Server Groups 12-15
RADIUS Authorization for User Privileged Access and Network Services 12-16
RADIUS Accounting 12-16
Establishing a Session with a Router if the AAA Server is Unreachable 12-16
Vendor-Specific RADIUS Attributes 12-16
Vendor-Proprietary RADIUS Server Communication 12-17
Switch Access with Kerberos 12-17
Understanding Kerberos 12-17
Kerberos Operation 12-19
Kerberos Configuration 12-20
Local Authentication and Authorization 12-20
Secure Shell 12-21
SSH 12-21
SSH Servers, Integrated Clients, and Su pported Versions 12-21
Limitations 12-22
SSH Configuration Guidelines 12-22
Switch for Secure Socket Layer HTTP 12-22
Secure HTTP Servers and Clients 12-22
Default SSL Settings 12-23
Certificate Authority Trustpoints 12-23
CipherSuites 12-24
Secure Copy Protocol 12-24
How to Configure Switch-Based Authentication 12-26
Configuring Password Protection 12-26