60Configuring AAA for Administrative and Local Access

Authenticating at the Console

You can configure the console so that authentication is required, or so that no authentication is required. Nortel recom- mends that you enforce authentication on the console port.

To enforce console authentication, take the following steps:

1Add a user in the local database by typing the following command with a username and password:

23x0# set user username password password success: change accepted.

2To enforce the use of console authentication through the local database, type the following command:

Caution! If you type this command before you have created a local username and password, you can lock yourself out of the WSS. Before entering this command, you must configure a local username and password.

23x0# set authentication console * local

3To store this configuration into nonvolatile memory, type the following command:

23x0# save config

success: configuration saved.

By default, no authentication is required at the console. If you have previously required authentication and have decided not to require it (during testing, for example), type the following command to configure the console so that it does not require username and password authentication:

23x0# set authentication console * none

Note. The authentication method none you can specify for administrative access is different from the fallthru authentication type None, which applies only to network access. The authentication method none allows access to the WSS switch by an administrator. The fallthru authentication type None denies access to a network user. (For information about the fallthru authentication types, see “Authentication Algorithm” on page 4039.)

320657-A

Page 60
Image 60
Nortel Networks 2300 manual Authenticating at the Console, 23x0# set authentication console * local