Cisco AS5800 Specifications Page 171

  • Download
  • Add to my manuals
  • Print
  • Page
    / 334
  • Table of contents
  • TROUBLESHOOTING
  • BOOKMARKS
  • Rated. / 5. Based on customer reviews
Page view 170
4-33
Cisco AS5800 Operations, Administration, Maintenance, and Provisioning Guide
DOC-7810814=
Chapter 4 Administration
Access Service Security
Users Dialing In Using PPP
The following example creates a TACACS+ authentication list for users connecting to interfaces
configured for dial-in using PPP. The name of the list is marketing. This example specifies that a remote
TACACS+ daemon be used as the security database. If this security database is not available, the
Cisco IOS software then polls the RADIUS daemon. Users are not authenticated if they are already
authenticated on a TTY line.
5800-1(config)# aaa authentication ppp marketing if-needed tacacs+ radius
In this example, default can be substituted for marketing if the administrator wants this list to be the
default list.
Applying Authentication Method Lists
As described in Defining Authentication Method Lists, page 4-29, the aaa authentication global
configuration command creates authentication method lists or profiles. You apply these authentication
method lists to lines or interfaces by issuing the login authentication or ppp authentication command,
as described in Table 4-5.
You can create more than one authentication list or profile for login and protocol authentication and
apply them to different lines or interfaces. The following examples show the line or interface
authentication commands that correspond to the aaa authentication global configuration command.
Login Authentication Example
The following example shows the default log-in authentication list applied to the console port and the
default virtual terminal (VTY) lines on the Cisco AS5800:
5800-1(config)# aaa authentication login default local
5800-1(config)# line console 0
5800-1(config-line)# login authentication default
5800-1(config-line)# line vty 0 69
5800-1(config-line)# login authentication default
Table 4-5 Line and Interface Authentication Method Lists
Interface and Line
Command Action
Port to Which List Is
Applied
Corresponding Global
Configuration Command
login authentication Logs directly in to the Cisco AS5800 Console port or VTY
lines
aaa authentication login
ppp authentication
1
1. If you issued the ppp authentication command, you must specify either CHAP or PAP authentication. PAP is enabled by default, but Cisco recommends
that you use CHAP because CHAP is more secure. For more information, refer to the security configuration guide for your Cisco IOS release, which is
part of the Cisco IOS configuration guides and command references documentation.
Uses PPP to access IP or IPX network
resources
Interface aaa authentication ppp
Page view 170
1 2 ... 166 167 168 169 170 171 172 173 174 175 176 ... 333 334

Comments to this Manuals

No comments