HP procurve 2500 Benutzerhandbuch

Seite von 270
165    
Enhancements in Release F.02.02
TACACS+ Authentication for Centralized Control of Switch Access Security
TACACS+ Authentication for Centralized Control of Switch 
Access Security
TACACS+ Features
TACACS+ authentication enables you to use a central server to allow or deny access to Series 2500 
switches (and other TACACS-aware devices) in your network. This means that you can use a central 
database to create multiple unique username/password sets with associated privilege levels for use 
by  individuals who have reason to access the switch from either the switch’s console port (local 
access) or Telnet (remote access).  
N o t e
In release F.02.02, TACACS+ authentication does not affect Web browser interface access. For 
steps to block unauthorized access through the Web browser interface, see “Controlling Web 
Browser Interface Access When Using TACACS+ Authentication” on page 184.
Figure 82.   Example of TACACS+ Operation
Feature
Default
Menu
CLI
Web
view the switch’s authentication configuration
n/a
    —
    —
view the switch’s TACACS+ server contact configuration
n/a
    —
    —
configure the switch’s authentication methods
disabled
    —
    —
configure the switch to contact TACACS+ server(s)
disabled
    —
    —
   
B
Series 2500 Switch 
Configured for 
TACACS+ Operation
Terminal "A" Directly 
Accessing the Switch 
Via Switch’s Console 
Port
Terminal  "B" Remotely Accessing The Switch Via Telnet
   
A
Primary 
TACACS+ 
Server
The switch passes the login 
requests from terminals A and B 
to the TACACS+ server for 
authentication.  The TACACS+ 
server determines whether to 
allow access to the switch and 
what privilege level to allow for 
a given access request.
Access Request                                                                  A1 - A4 :  Path for Request from       
                                                                                                     Terminal A (Through Console Port) 
TACACS Server                                                               B1 - B4: Path for Request from      
Response                                                                              Terminal B (Through Telnet)     
B1
A2 or 
B2
A3 or 
B3
B4
A1
A4