AI232 Version 9.6x User’s Guide
AI232 Local Menu System: Identifying AI232 Menu System Security Options
3-2
Identifying AI232 Menu System Security Options
AI232 has a variety of security options, including:
zMultilevel User Name and Password Security
zRADIUS Authentication
zTACACS+ Authentication
zPPP Authentication Protocols (PAP and CHAP)

Multilevel User Name and Password Security

Up to 10 configurable user account profiles can be assigned to an AI232 user. Five
system profiles are available for providing various levels of user access. For more
information about user profiles, refer to command profile on page 1-103.

RADIUS Authentication

RADIUS authentication verifies user login information against valid user information in
a database on a centralized RADIUS authentication server. A primary and secondary
RADIUS server are configurable to provide secure access for an entire AI232
network. AI232 RADIUS authentication is available for Telnet, asynchronous, and
synchronous ports. For more information on RADIUS authentication, refer to section
RADIUS Configuration on page 1-19.

TACACS+ Authentication

TACACS+ authentication verifies user login information against the user’s permission
level on a TACACS+ server. Up to 9 TACACS+ servers are configurable to provide
secure access for an entire AI232 network. AI232 TACACS+ authentication is
available for Telnet, asynchronous, and FTP connections. For more information on
TACACS+ authentication and server configuration, refer to the following commands:
zaaa authen on page 8-7 ztacacs server on page 8-96
zaaa author on page 8-8 ztacacs server phase on page 8-98
zaaa fallback on page 8-10 ztacacs server ip on page 8-97
zaaa timeout on page 8-19 ztacacs server port on page 8-100
zaaa ppp authen on page 8-11 ztacacs server secret on page 8-101