Enterasys D-Series CLI Reference 17-1
17
Security Configuration
ThischapterdescribestheSecurityConfigurationsetofcommandsandhowtousethem.

Overview of Security Methods

Thefollowingsecuritymethodsareavailableforcontrollingwhichusersareallowedtoaccess,
monitor,andmanagetheswitch.
•LoginuseraccountsandpasswordsusedtologintotheCLIviaaTelnetconnectionorlocal
COMportconnection.Fordetails,refertoSettingUserAccountsandPasswords on
page32.
•HostAccessControlAuthentication(HACA)authenticatesuseraccessofTelne t
management,consolelocalmanagementandWebVie wviaacentralRADIUSClient/Server
application.WhenRADIUSisenabled,thisessentiallyoverridesloginuseraccounts.When
HACAisactiveperavalidRADIUSconfiguration,theusernamesandpasswordsusedto
accesstheswitchviaTelne t,SSH,Web View, andCOMportswillbevalidatedagainstthe
configuredRADIUSserver.OnlyinthecaseofaRADIUStimeoutwillthosecredentialsbe
comparedagainstcredentialslocallyconfiguredontheswitch.Fordetails,referto
ConfiguringRADIUSonpage 173.
•SNMPuserorcommunitynamesallowsaccesstotheDSeriesswitchviaanetworkSNMP
managementapplication.Toaccesstheswitch,youmustenteranSNMPuserorcommunity
namestring.Thelevelofmanagementaccessisdependentontheassociatedaccesspolicy.For
details,refertoChapter7.
• 802.1XPortBasedNetworkAccessControlusingEAPOL(ExtensibleAuthenticationProtocol)
providesamechanismviaaRADIUSserverforadministratorstosecurelyauthenticateand
grantappropriateaccesstoenduserdevicescommunicatingwithDSeriesports.Fordetails
For information about... Refer to page...
Overview of Security Methods 17-1
Configuring RADIUS 17-3
Configuring 802.1X Authentication 17-11
Configuring MAC Authentication 17-21
Configuring Multiple Authentication Methods 17-33
Configuring VLAN Authorization (RFC 3580) 17-45
Configuring MAC Locking 17-51
Configuring Port Web Authentication (PWA) 17-62
Configuring Secure Shell (SSH) 17-74