Extreme 3804 User Guide

Page of 244
 
56
Summit24e3 Switch Installation and User Guide
Managing the Switch
Authenticating Users 
ExtremeWare provides two methods to authenticate users who login to the switch:
Radius client 
TACACS+ 
RADIUS Client 
Remote Authentication Dial In User Service (RADIUS, RFC 2138) is a mechanism for authenticating and 
centrally administrating access to network nodes. The ExtremeWare RADIUS client implementation 
allows authentication for Telnet or console access to the switch.
NOTE
You cannot configure RADUIS and TACACS+ at the same time. 
You can define a primary and secondary RADIUS server for the switch to contact. When a user 
attempts to login using Telnet, http, or the console, the request is relayed to the primary RADIUS server, 
and then to the secondary RADIUS server, if the primary does not respond. If the RADIUS client is 
enabled, but access to the RADIUS primary an secondary server fails, the switch uses its local database 
for authentication.
The privileges assigned to the user (admin versus nonadmin) at the RADIUS server take precedence 
over the configuration in the local switch database. 
Per-Command Authentication Using RADIUS 
The RADIUS implementation can be used to perform per-command authentication. Per-command 
authentication allows you to define several levels of user capabilities by controlling the permitted 
command sets based on the RADIUS username and password. You do not need to configure any 
additional switch parameters to take advantage of this capability. The RADIUS server implementation 
automatically negotiates the per-command authentication capability with the switch. For examples on 
per-command RADIUS configurations, see “Configuring RADIUS Client” on page 56.
Configuring RADIUS Client 
You can define primary and secondary server communication information, and for each RADIUS server, 
the RADIUS port number to use when talking to the RADIUS server. The default port value is 1645. The 
client IP address is the IP address used by the RADIUS server for communicating back to the switch.
RADIUS commands are described in Table 15.