HP 6125G HP 6125G & 6125G/XG Blade Switches Security Configuration Gui - Page 68

Level switching authentication for Telnet users by an HWTACACS server, Network requirements

Page 68 highlights

Total 1 connection matched. As the Authorized VLAN field in the output shows, VLAN 4 has been assigned to the user. Level switching authentication for Telnet users by an HWTACACS server Network requirements As shown in Figure 20, configure the switch to: • Use local authentication for the Telnet user and assign the privilege level of 0 to the user after the user passes authentication. • Use the HWTACACS server for level switching authentication of the Telnet user, and use local authentication as the backup. Figure 20 Network diagram Configuration considerations 1. Configure the switch to use AAA, particularly, local authentication for Telnet users: { Create ISP domain bbb and configure it to use local authentication for Telnet users. { Create a local user account, configure the password, and assign the user privilege level. 2. On the switch, configure the authentication method for user privilege level switching: { Specify to use HWTACACS authentication and, if HWTACACS authentication is not available, use local authentication for user level switching authentication. { Configure HWTACACS scheme hwtac and assign an IP address to the HWTACACS server. Set the shared keys for message exchange and specify that usernames sent to the HWTACACS server carry no domain name. Configure the domain to use the HWTACACS scheme hwtac for user privilege level switching authentication. { Configure the password for local privilege level switching authentication. 3. On the HWTACACS server, add the username and password for user privilege level switching authentication. Configuration procedure 1. Configure the switch: # Configure the IP address of VLAN-interface 2, through which the Telnet user accesses the switch. system-view [Switch] interface vlan-interface 2 58

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285

58
Total 1 connection matched.
As the
Authorized VLAN
field in the output shows, VLAN 4 has been assigned to the user.
Level switching authentication for Telnet users by an
HWTACACS server
Network requirements
As shown in
Figure 20
, configure the switch to:
Use local authentication for the Telnet user and assign the privilege level of 0 to the user after the
user passes authentication.
Use the HWTACACS server for level switching authentication of the Telnet user, and use local
authentication as the backup.
Figure 20
Network diagram
Configuration considerations
1.
Configure the switch to use AAA, particularly, local authentication for Telnet users:
{
Create ISP domain
bbb
and configure it to use local authentication for Telnet users.
{
Create a local user account, configure the password, and assign the user privilege level.
2.
On the switch, configure the authentication method for user privilege level switching:
{
Specify to use HWTACACS authentication and, if HWTACACS authentication is not available,
use local authentication for user level switching authentication.
{
Configure HWTACACS scheme
hwtac
and assign an IP address to the HWTACACS server. Set
the shared keys for message exchange and specify that usernames sent to the HWTACACS
server carry no domain name. Configure the domain to use the HWTACACS scheme
hwtac
for
user privilege level switching authentication.
{
Configure the password for local privilege level switching authentication.
3.
On the HWTACACS server, add the username and password for user privilege level switching
authentication.
Configuration procedure
1.
Configure the switch:
# Configure the IP address of VLAN-interface 2, through which the Telnet user accesses the switch.
<Switch> system-view
[Switch] interface vlan-interface 2