HP 8/20q HP StorageWorks 8/20q and SN6000 Fibre Channel Switch Enterprise Fabr - Page 75

Adding a RADIUS server

Page 75 highlights

RADIUS server and can be managed centrally and separately from the clients. In addition, no passwords are exchanged between the RADIUS server and its clients. Authentication of requests from a RADIUS client to the server and responses from the server to a client can also be authenticated. This requires sharing a secret between the server and client. The accounting RADIUS supports the auditing of the users and switch services such as Telnet, FTP, and switch management applications. NOTE: The RADIUS server dialog boxes are available only on a secure (SSL) fabric and on the entry switch. For more information about SSL, see "Connection security" (page 65). For information about the SSL service, see "Managing system services" (page 97). You may need to configure a security set for RADIUS device security to be used in authenticating other switches. For information about configuring a security set, see "Creating a security set" (page 70). Adding a RADIUS server When you add a RADIUS server, you provide a method to centralize the management of authentication passwords over a network. Figure 38 Radius Server Information dialog box-Add server To add a RADIUS server: 1. Select a switch in the fabric tree. 2. Select Switch > Radius Servers to open the Radius Server Information dialog box (Figure 38). 3. Click the Add Server tab, and select the server type (Device, User, Account). 4. In the Server Address field, enter the remote IP address of the server. 5. In the UDP Port field, enter the remote UDP port number of the Authentication Radius Server. The Radius Accounting Server UDP port is the value of Device/User Authentication Server UDP Port plus one. 6. In the Timeout field, enter the timeout value in seconds (minimum of 1 second, maximum of 30 seconds). This is the number of seconds the RADIUS client waits for a response from the RADIUS server before retrying, or giving up on a request. 7. In the Retries field, enter the number of retries. This is the maximum number of times the RADIUS client retries a request sent to the primary RADIUS server. 8. Select the Sign Packets option to enable the switch to include a digital signature (Message-Authenticator) in all RADIUS access request packets sent to the RADIUS server. A valid Message-Authenticator attribute is required in all RADIUS server responses. HP StorageWorks 8/20q and SN6000 Fibre Channel Switch Enterprise Fabric Management Suite User Guide 75

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160

HP StorageWorks 8/20q and SN6000 Fibre Channel Switch Enterprise Fabric Management Suite User Guide
75
RADIUS server and can be managed centrally and separately from the clients. In addition, no passwords
are exchanged between the RADIUS server and its clients. Authentication of requests from a RADIUS client
to the server and responses from the server to a client can also be authenticated. This requires sharing a
secret between the server and client. The accounting RADIUS supports the auditing of the users and switch
services such as Telnet, FTP, and switch management applications.
NOTE:
The RADIUS server dialog boxes are available only on a secure (SSL) fabric and on the entry
switch. For more information about SSL, see ”
Connection security
” (page 65). For information about the
SSL service, see ”
Managing system services
” (page 97). You may need to configure a security set for
RADIUS device security to be used in authenticating other switches. For information about configuring a
security set, see ”
Creating a security set
” (page 70).
Adding a RADIUS server
When you add a RADIUS server, you provide a method to centralize the management of authentication
passwords over a network.
Figure 38
Radius Server Information dialog box—Add server
To add a RADIUS server:
1.
Select a switch in the fabric tree.
2.
Select
Switch > Radius Servers
to open the Radius Server Information dialog box (
Figure 38
).
3.
Click the
Add Server
tab, and select the server type (Device, User, Account).
4.
In the Server Address field, enter the remote IP address of the server.
5.
In the UDP Port field, enter the remote UDP port number of the Authentication Radius Server. The Radius
Accounting Server UDP port is the value of Device/User Authentication Server UDP Port plus one.
6.
In the Timeout field, enter the timeout value in seconds (minimum of 1 second, maximum of 30
seconds). This is the number of seconds the RADIUS client waits for a response from the RADIUS server
before retrying, or giving up on a request.
7.
In the Retries field, enter the number of retries. This is the maximum number of times the RADIUS client
retries a request sent to the primary RADIUS server.
8.
Select the
Sign Packets
option to enable the switch to include a digital signature
(Message-Authenticator) in all RADIUS access request packets sent to the RADIUS server. A valid
Message-Authenticator attribute is required in all RADIUS server responses.