Configuring Authentication on the Switch
•
•
•
•
Authentication Default Configuration
Table 39-2
Table 39-2
Feature
Login authentication (console and Telnet)
Local authentication (console and Telnet)
Local user authentication
TACACS+ login authentication (console and Telnet)
TACACS+ enable authentication (console and Telnet)
TACACS+ key
TACACS+ login attempts
TACACS+ server timeout
TACACS+ directed request
RADIUS login authentication (console and Telnet)
RADIUS enable authentication (console and Telnet)
RADIUS server IP address
RADIUS server UDP auth-port
RADIUS key
RADIUS server timeout
RADIUS server dead time
RADIUS retransmit attempts
Kerberos login authentication (console and Telnet)
Kerberos enable authentication (console and Telnet)
Kerberos server IP address
Kerberos DES key
Kerberos server auth-port
Kerberos local-realm name
Kerberos credentials forwarding
Kerberos clients mandatory
Kerberos preauthentication
Catalyst 6500 Series Switch Software Configuration Guide—Release 8.7
39-10
Configuring TACACS+ Authentication, page 39-19
Configuring RADIUS Authentication, page 39-25
Configuring Kerberos Authentication, page 39-33
Authentication Example, page 39-43
shows the default authentication configuration.
Authentication Default Configuration
Chapter 39
Configuring the Switch Access Using AAA
Default Value
Enabled
Enabled
Disabled
Disabled
Disabled
None specified
3
5 seconds
Disabled
Disabled
Disabled
None specified
Port 1812
None specified
5 seconds
0 (servers not marked dead)
2 times
Disabled
Disabled
None specified
None specified
Port 750
NULL string
Disabled
Not mandatory
Disabled
OL-8978-04