HP 200 Unified Threat Management (UTM) Appliance Series Guía de inicio rápido Pagina 143

  • Descarga
  • Añadir a mis manuales
  • Imprimir
  • Pagina
    / 150
  • Tabla de contenidos
  • SOLUCIÓN DE PROBLEMAS
  • MARCADORES
  • Valorado. / 5. Basado en revisión del cliente
Vista de pagina 142
137
Configuring the authentication parameters for user privilege level switching
A user can switch to a lower privilege level without authentication. To switch to a higher privilege level,
however, a user must provide the privilege level switching authentication information (if any). Table 29
sh
ows the privilege level switching authentication modes supported by the device.
Table 29 Privilege level switching authentication modes
Authentication mode Ke
y
words
Descri
p
tion
Local password
authentication only
(local-only)
local
The device uses the locally configured passwords for privilege level
switching authentication.
To use this mode, you must set the passwords for privilege level
switching using the super password command.
Remote AAA
authentication through
HWTACACS or
RADIUS
scheme
The device sends the username and password for privilege level
switching to the HWTACACS or RADIUS server for remote
authentication.
To use this mode, you must perform the following configuration tasks:
Configure the required HWTACACS or RADIUS schemes and
configure the ISP domain to use the schemes for users. For more
information, see Access Control Configuration Guide.
Add user accounts and specify the user passwords on the
HWTACACS or RADIUS server.
Local password
authentication first and
then remote AAA
authentication
local
scheme
The device first uses the locally configured passwords for privilege
level switching authentication. If no local password is set, the device
allows console users to switch their privilege levels without
authentication, but performs AAA authentication for VTY users.
Remote AAA
authentication first and
then local password
authentication
scheme
local
AAA authentication is performed first, and if the remote HWTACACS
or RADIUS server does not respond or AAA configuration on the
device is invalid, the local password authentication is performed.
To configure the authentication parameters for a user privilege level:
Ste
p
Command
Remarks
1. Enter system view.
system-view N/A
2. Set the authentication
mode for user privilege
level switching.
super authentication-mode
{ local | scheme } *
Optional.
By default, local-only authentication is used.
3. Configure the password
for the user privilege
level.
super password [ level
user-level ] { cipher |
simple } password
If local authentication is involved, this step is
required.
By default, a privilege level has no password.
If no user privilege level is specified when you
configure the command, the user privilege
level defaults to 3.
If local-only authentication is used, a console user interface user can switch to a higher privilege level,
even if the privilege level has not been assigned a password.
Vista de pagina 142

Comentarios a estos manuales

Sin comentarios