Authentication Commands 4

Authentication Commands

You can configure this switch to authenticate users logging into the system for management access using local or RADIUS authentication methods. You can also enable port-based authentication for network client access using IEEE 802.1x.

Table 4-26. Authentication Commands

Command Group

Function

Page

Authentication Sequence

Defines logon authentication method and precedence

4-67

 

 

 

RADIUS Client

Configures settings for authentication via a RADIUS server

4-69

 

 

 

TACACS+ Client

Configures settings for authentication via a TACACS+ server

4-73

 

 

 

Port Security

Configures secure addresses for a port

4-75

 

 

 

Port Authentication

Configures host authentication on specific ports using 802.1x

4-77

 

 

 

Authentication Sequence

Table 4-27. Authentication Sequence

Command

Function

Mode

Page

authentication login

Defines logon authentication method and precedence

GC

4-67

 

 

 

 

authentication enable

Defines the authentication method and precedence for

GC

4-68

 

command mode change

 

 

authentication login

This command defines the login authentication method and precedence. Use the no form to restore the default.

Syntax

authentication login {[local] [radius] [tacacs]} no authentication login

local - Use local password.

radius - Use RADIUS server password.

tacacs - Use TACACS server password.

Default Setting

Local

Command Mode

Global Configuration

Command Usage

RADIUS uses UDP while TACACS+ uses TCP. UDP only offers best effort delivery, while TCP offers a connection-oriented transport. Also, note that RADIUS encrypts only the password in the access-request packet from the client to the server, while TACACS+ encrypts the entire body of the packet.

4-67

Page 243
Image 243
SMC Networks 16 10BASE-T, 100BASE-TX manual Authentication Commands, Authentication Sequence, Authentication login