HP StorageWorks 2/16V HP StorageWorks Fabric OS 5.3.x administrator guide (569 - Page 80

How to add a RADIUS server to the switch configuration, How to enable and disable a RADIUS server

Page 80 highlights

How to add a RADIUS server to the switch configuration 1. Connect to the switch and log in as admin. 2. Enter this command: switch:admin> aaaConfig --add server [-p port] [-s secret] [-t timeout] [-a pap | chap] server Enter either a server name or IP address. Avoid duplicating server listings (that is, listing the same server once by name and again by IP address). Up to five servers can be added to the configuration. -p port Optionally, enter a server port. The default is port 1812. -s secret Optionally, enter a shared secret. The default is "sharedsecret". Secrets can be from 8 to 40 alphanumeric characters long. Make sure that the secret matches that configured on the server. -t timeout Optionally, enter the length of time (in seconds) that the server has to respond before the next server is contacted. The default is three seconds. Time-out values can range from 1 to 30 seconds. -a[pap|chap]peap Specify PAP, CHAP or PEAP as authentication protocol. Use -mschapv2 peap-mschapv2 to provide encrypted authentication channel between switch and server. At least one RADIUS server must be configured before you can enable RADIUS service. If no RADIUS configuration exists, turning it on triggers an error message. When the command succeeds, the event log indicates that the configuration is enabled or disabled. CAUTION: When the RADIUS authentication mode is set to radiuslocal, you cannot downgrade Fabric OS to any version lower than v5.2.x: previous versions do not support the radiuslocal mode. How to enable and disable a RADIUS server 1. Connect to the switch and log in as admin. 2. Enter this command to enable RADIUS + local: switch:admin> aaaconfig --radiuslocal Local is used if the user authentication fails on the RADIUS server. Or to enable RADIUS + localbackup: switch:admin> aaaconfig --radiuslocalbackup Local is used if the RADIUS servers are not accessible. How to delete a RADIUS server from the configuration 1. Connect to the switch and log in as admin. 2. Enter this command: switch:admin> aaaConfig --remove server | all server Enter either the name or IP address of the server to be removed. 3. At the prompt, enter y to complete the command. When the command succeeds, the event log indicates that the server is removed. 82 Managing user accounts

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336
  • 337
  • 338
  • 339
  • 340
  • 341
  • 342
  • 343
  • 344
  • 345
  • 346
  • 347
  • 348
  • 349
  • 350
  • 351
  • 352
  • 353
  • 354
  • 355
  • 356
  • 357
  • 358
  • 359
  • 360
  • 361
  • 362
  • 363
  • 364
  • 365
  • 366
  • 367
  • 368
  • 369
  • 370
  • 371
  • 372
  • 373
  • 374
  • 375
  • 376
  • 377
  • 378
  • 379
  • 380
  • 381
  • 382
  • 383
  • 384
  • 385
  • 386
  • 387
  • 388
  • 389
  • 390
  • 391
  • 392
  • 393
  • 394
  • 395
  • 396
  • 397
  • 398
  • 399
  • 400
  • 401
  • 402
  • 403
  • 404
  • 405
  • 406
  • 407
  • 408
  • 409
  • 410
  • 411
  • 412
  • 413
  • 414
  • 415
  • 416
  • 417
  • 418
  • 419
  • 420
  • 421
  • 422
  • 423
  • 424
  • 425
  • 426
  • 427
  • 428
  • 429
  • 430
  • 431
  • 432
  • 433
  • 434
  • 435
  • 436
  • 437
  • 438
  • 439
  • 440
  • 441
  • 442
  • 443
  • 444
  • 445
  • 446
  • 447
  • 448
  • 449
  • 450
  • 451
  • 452
  • 453
  • 454
  • 455
  • 456
  • 457
  • 458
  • 459
  • 460
  • 461
  • 462
  • 463
  • 464
  • 465

82
Managing user accounts
How to add a RADIUS server to the switch configuration
1.
Connect to the switch and log in as
admin
.
2.
Enter this command:
At least one RADIUS server must be configured before you can enable RADIUS service.
If no RADIUS configuration exists, turning it on triggers an error message. When the command succeeds,
the event log indicates that the configuration is enabled or disabled.
CAUTION:
When the RADIUS authentication mode is set to
radiuslocal
, you cannot downgrade
Fabric OS to any version lower than v5.2.x: previous versions do not support the
radiuslocal
mode.
How to enable and disable a RADIUS server
1.
Connect to the switch and log in as admin.
2.
Enter this command to enable RADIUS + local:
Local is used if the user authentication fails on the RADIUS server. Or to enable RADIUS + localbackup:
Local is used if the RADIUS servers are not accessible.
How to delete a RADIUS server from the configuration
1.
Connect to the switch and log in as admin.
2.
Enter this command:
3.
At the prompt, enter
y
to complete the command.
When the command succeeds, the event log indicates that the server is removed.
switch:admin>
aaaConfig --add
server
[
-p
port
] [
-s
secret
] [
-t
timeout
]
[
-a pap
|
chap
]
server
Enter either a server name or IP address. Avoid duplicating server listings
(that is, listing the same server once by name and again by IP address).
Up to five servers can be added to the configuration.
-p port
Optionally, enter a server port. The default is port 1812.
-s secret
Optionally, enter a shared secret. The default is “sharedsecret”. Secrets can
be from 8 to 40 alphanumeric characters long. Make sure that the secret
matches that configured on the server.
-t timeout
Optionally, enter the length of time (in seconds) that the server has to
respond before the next server is contacted. The default is three seconds.
Time-out values can range from 1 to 30 seconds.
-a[pap|chap]peap
-mschapv2
Specify PAP, CHAP or PEAP as authentication protocol. Use
peap-mschapv2 to provide encrypted authentication channel between
switch and server.
switch:admin> aaaconfig --radiuslocal
switch:admin> aaaconfig --radiuslocalbackup
switch:admin>
aaaConfig --remove
server
|
all
server
Enter either the name or IP address of the server to be removed.