51

Configuring AAA for

Administrative and Local

Access

Overview of AAA for Administrative and Local Access . . . . . . . . . . . . . . . . . . . . . . 51 Before You Start . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 53 About Administrative Access . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 54 First-Time Configuration using the Console . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 56 Configuring Accounting for Administrative Users . . . . . . . . . . . . . . . . . . . . . . . . . . . 63 Displaying the AAA Configuration . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 65 Saving the Configuration . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 65 Administrative AAA Configuration Scenarios . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 66

Overview of AAA for Administrative and Local Access

Nortel WLAN 2300 System Software (WSS Software) supports authentication, authorization, and accounting (AAA) for secure network connections. As administrator, you must establish administrative access for yourself and optionally other local users before you can configure the WSS for operation.

Here is an overview of configuration topics:

1Console connection. By default, any administrator can connect to the console port and manage the switch, because no authentication is enforced. (Nortel recommends that you enforce authentication on the console port after initial connection.)

2Telnet or SSH connection. Administrators cannot establish a Telnet or Secure Shell (SSH) connection to the WSS by default. To provide Telnet or SSH access, you must add a username and password entry to the local database or, optionally, set the authentication method for Telnet users to a Remote Authentication Dial-In User Service (RADIUS) server.

Note. A CLI Telnet connection to the WSS is not secure, unlike SSH, WLAN Management Software and Web View connections. (For details, see Chapter , “Managing Keys and Certificates,” on page 379.)

3Restricted mode. When you initially connect to the WSS, your mode of operation is restricted. In this mode, only a small subset of status and monitoring commands is available. Restricted mode is useful for

Nortel WLAN Security Switch 2300 Series Configuration Guide

Page 51
Image 51
Nortel Networks 2300 manual Configuring AAA for Administrative and Local Access