Contents
xiii
Cisco IE 2000 Switch Software Configuration Guide
OL-25866-01
Setting or Changing a Static Enable Password 12-26
Protecting Enable and Enable Secret Passwords with Encryption 12-27
Disabling Password Recovery 12-27
Setting a Telnet Password for a Terminal Line 12-28
Configuring Username and Password Pairs 12-28
Setting the Privilege Level for a Command 12-29
Changing the Default Privilege Level for Lines 12-29
Logging Into and Exiting a Privilege Level 12-30
Configuring TACACS+ 12-30
Identifying the TACACS+ Server Host and Setting the Authentication Key 12-30
Configuring TACACS+ Login Authentication 12-31
Configuring TACACS+ Authorization for Privileged EXEC Access and Network Services 12-33
Starting TACACS+ Accounting 12-33
Configuring Radius Server Communication 12-33
Defining AAA Server Groups 12-35
Configuring RADIUS Login Authentication 12-36
Configuring RADIUS Authorization for User Privileged Access and Network Services 12-37
Starting RADIUS Accounting 12-37
Configuring Settings for All RADIUS Servers 12-37
Configuring the Switch for Vendor-Proprietary RADIUS Server Communication 12-38
Configuring CoA on the Switch 12-38
Configuring the Switch for Local Authentication and Authorization 12-39
Configuring Secure Shell 12-40
Setting Up the Switch to Run SSH 12-40
Configuring the SSH Server 12-40
Configuring Secure HTTP Servers and Clients 12-42
Configuring a CA Trustpoint 12-42
Configuring the Secure HTTP Server 12-42
Configuring the Secure HTTP Client 12-44
Monitoring and Maintaining Switch-Based Authentication 12-44
Configuration Examples for Configuring Switch-Based Authentication 12-45
Changing the Enable Password: Example 12-45
Configuring the Encrypted Password: Example 12-45
Setting the Telnet Password for a Terminal Line: Example 12-45
Setting the Privilege Level for a Command: Example 12-45
Configuring the RADIUS Server: Examples 12-45
Defining AAA Server Groups: Example 12-46
Configuring Vendor-Specific RADIUS Attributes: Examples 12-46
Configuring a Vendor-Proprietary RADIUS Host: Example 12-46
Sample Output for a Self-Signed Certificate: Example 12-46