D-Series CLI Reference 15-1
15
Security Configuration
ThischapterdescribestheSecurityConfigurationsetofcommandsandhowtousethem.

Overview of Security Methods

Thefollowingsecuritymethodsareavailableforcontrollingwhichusersareallowedtoaccess,
monitor,andmanagetheswitch.
•LoginuseraccountsandpasswordsusedtologintotheCLIviaaTelnet connectionorlocal
COMportconnection.Fordetails,refertoSettingUserAccountsandPassword son
page 22.
•HostAccessControlAuthentication(HACA)authenticatesuseraccessofTelne t
management,consolelocalmanagementandWebVi ewviaacentralRADIUSClient/Server
application.WhenRADIUSisenabled,thisessentiallyoverridesloginuseraccounts.When
HACAisactiveperavalidRADIUSconfiguration,theusernamesandpasswordsusedto
accesstheswitchviaTeln et, SSH,WebVi ew,andCOMportswillbevalidatedagainstthe
configuredRADIUSserver.OnlyinthecaseofaRADIUStimeoutwillthosecredentialsbe
comparedagainstcredentialslocallyconfiguredontheswitch.Fordetails,referto
ConfiguringRADIUSonpage 153.
•SNMPuserorcommunitynamesallowsaccesstotheDSeriesswitchviaanetworkSNMP
managementapplication.Toaccesstheswitch,youmustenteranSNMPuserorcommunity
namestring.Thelevelofmanagementaccessisdependentontheassociatedaccesspolicy.For
details,refertoChapter 5.
• 802.1XPortBasedNetworkAccessControlusingEAPOL(ExtensibleAuthentication
Protocol)providesamechanismviaaRADIUSserverforadministratorstosecurely
authenticateandgrantappropriateaccesstoenduserdevicescommunicatingwithDSeries
For information about... Refer to page...
Overview of Security Methods 15-1
Configuring RADIUS 15-3
Configuring 802.1X Authentication 15-9
Configuring MAC Authentication 15-19
Configuring Multiple Authentication Methods 15-30
Configuring VLAN Authorization (RFC 3580) 15-41
Configuring MAC Locking 15-46
Configuring Port Web Authentication (PWA) 15-57
Configuring Secure Shell (SSH) 15-68