SmartConnect User’s Guide

SSH/SCP Integration with Radius Authentication

SSH/SCP is integrated with RADIUS authentication. After the RADIUS server is enabled on the switch, all subsequent SSH authentication requests will be redirected to the specified RADIUS servers for authentication. The redirection is transparent to the SSH clients.

SSH/SCP Integration with TACACS+ Authentication

SSH/SCP is integrated with TACACS+ authentication. After the TACACS+ server is enabled on the SmartConnect, all subsequent SSH authentication requests will be redirected to the specified TACACS+ servers for authentication. The redirection is transparent to the SSH cli- ents.

SecurID Support

SSH/SCP can also work with SecurID, a token card-based authentication method. The use of SecurID requires the interactive mode during login, which is not provided by the SSH connec- tion.

Note – There is no BBI support for SecurID because the SecurID server, ACE, is a one-time password authentication and requires an interactive session.

Using SecurID with SSH

Using SecurID with SSH involves the following tasks.

„To log in using SSH, use a special user name, “ace,” to bypass the SSH authentication.

„After a SSH connection is established, you are prompted to enter the user name and pass- word (the SecurID authentication is being performed now).

„Provide your user name and the token in your SecurID card as a regular Telnet user.

84 „ Chapter 6: Configuring Switch Access

BMD00082, February 2009

Page 86
Image 86
IBM Partner Pavilion BMD00082 SSH/SCP Integration with Radius Authentication, SecurID Support, Using SecurID with SSH