Chapter 9 Configuring Authentication

Creating Named Server Groups

Creating Named Server Groups

By default, you can use all configured RADIUS or TACACS+ servers for authentication. All configured RADIUS servers belong to the default group named radius. All configured TACACS+ servers belong to the default group named tacacs+.

You can also create named groups of RADIUS or TACACS+ servers, to be used for specific authentication purposes. For example, you can use a subset of all configured RADIUS servers for iSCSI authentication of IP hosts requesting access to storage via a specific SCSI routing instance.

In the example configuration shown in Figure 9-2, the group of RADIUS servers named janus and the default group of all TACACS+ servers will be used for iSCSI authentication of IP hosts accessing storage via the SCSI routing instance named zeus. In the example configurations shown in Figure 9-5and Figure 9-7, the group of TACACS+ servers named sysadmin will be used for Enable and Login authentication.

Radius Server Groups

Use the commands in the following procedure to create a named group of RADIUS servers.

 

Command

Description

Step 1

 

 

enable

Enter Administrator mode.

Step 2

 

 

aaa group server radius janus

Create a group of RADIUS servers. For example create a group

 

 

named janus.

 

 

All authentication server groups must have unique names; you

 

 

cannot have a group of RADIUS servers named janus and a group

 

 

of TACACS+ servers named janus.

Step 3

 

 

aaa group server radius janus

Add a RADIUS server to the named group. For example, add the

 

server 10.5.0.61

RADIUS server at IP address 10.5.0.61 to the group named janus.

 

 

Because no port is specified, authentication requests to this server

 

 

use the default UDP port 1645. Servers are accessed in the order

 

 

in which they are defined within the named group.

Step 4

 

 

aaa group server radius janus

Add another RADIUS server to the named group. For example,

 

server 10.6.0.53

add the RADIUS server at IP address 10.6.0.53 to the group named

 

 

janus.

 

 

 

TACACS+ Server Groups

Use the commands in the following procedure to create a named group of TACACS+ servers.

 

Command

Description

Step 1

 

 

enable

Enter Administrator mode.

Step 2

 

 

aaa group server tacacs+

Create a group of TACACS+ servers. For example create a group

 

sysadmin

named sysadmin.

 

 

All authentication server groups must have unique names; you

 

 

cannot have a group of TACACS+ servers named sysadmin and a

 

 

group of RADIUS servers named sysadmin.

 

 

 

Cisco SN 5428-2 Storage Router Software Configuration Guide

 

OL-5239-01

9-15

 

 

 

Page 15
Image 15
Cisco Systems SN 5428-2 manual Creating Named Server Groups, Radius Server Groups, Aaa group server radius janus

SN 5428-2 specifications

Cisco Systems SN 5428-2 is a highly versatile and advanced network storage solution designed to meet the demands of data center environments. This robust storage appliance integrates cutting-edge technologies to provide high performance, reliability, and scalability, making it an ideal choice for organizations looking to enhance their data management capabilities.

One of the main features of the SN 5428-2 is its high-density architecture, which allows for efficient utilization of space while providing ample storage capacity. The system supports multiple drive configurations, including HDDs and SSDs, enabling users to tailor their storage solutions based on performance needs and budget constraints. With a significant amount of raw capacity available, organizations can effortlessly handle large volumes of data and support intensive workloads.

The SN 5428-2 boasts advanced data protection technologies, ensuring that critical information is safeguarded against loss or corruption. Features like RAID support provide redundancy and fault tolerance, while snapshot and cloning capabilities offer quick recovery options in case of data breaches or system failures. Additionally, built-in encryption features help protect sensitive data both at rest and in transit.

The appliance incorporates state-of-the-art networking capabilities as well. With support for various network protocols, including iSCSI and Fibre Channel, the SN 5428-2 can seamlessly integrate into existing infrastructures. This adaptability allows for easy connection with different servers and storage systems, facilitating a more cohesive and efficient operational environment.

Furthermore, the SN 5428-2 is designed with scalability in mind. Organizations can start with a basic configuration and expand as their storage needs grow by adding additional drives or connecting more appliances. This flexibility ensures that businesses can continue to meet their evolving data demands without the need for complete system overhauls.

Management and monitoring of the SN 5428-2 are simplified through a user-friendly interface that provides real-time insights into system performance, capacity utilization, and health status. Administrators can easily configure and manage storage resources, making operational tasks more efficient.

In summary, Cisco Systems SN 5428-2 stands out in the realm of storage solutions by combining high density, robust data protection, advanced networking capabilities, and remarkable scalability. Its thoughtful design and features make it an essential tool for organizations looking to enhance their data storage infrastructure and improve overall performance. With its reliable and efficient performance, the SN 5428-2 is well-suited for a wide array of data center applications.