Chapter 25 AAA
XMG1930 Series User’s Guide
217
Figure 150
Advanced Application > AAA > AAA Setup
The following table describes the labels in this screen.
Table 100 Advanced Application > AAA > AAA Setup
LABEL
DESCRIPTION
Authentication
Use this section to specify the methods used to authenticate users accessing the Switch.
Login
These fields specify which database the Switch should use (first and second) to authenticate
administrator accounts (users for Switch management).
Configure the local user accounts in the
Access Control
>
Logins
screen. The RADIUS is an
external server. Before you specify the priority, make sure you have set up the corresponding
database correctly first.
You can specify up to two methods for the Switch to authenticate administrator accounts. The
Switch checks the methods in the order you configure them (first
Method 1
, and then
Method
2
). You must configure the settings in the
Method 1
field. If you want the Switch to check
another source for administrator accounts, specify them in the
Method 2
field.
Select
local
to have the Switch check the administrator accounts configured in the
Access
Control
>
Logins
screen.
Select
radius
to have the Switch check the administrator accounts configured through your
RADIUS server.
Authorization
Use this section to configure authorization settings on the Switch.
Type
Set whether the Switch provides the following services to a user.
•
Exec
: Allow an administrator which logs into the Switch through Telnet or SSH to have a
different access privilege level assigned through the external server.
•
Dot1x
: Allow an IEEE 802.1x client to have different bandwidth limit or VLAN ID assigned
through the external server.
Active
Select this to activate authorization for a specified event type.
Method
RADIUS is the only method for authorization of the
Exec
type of service.
Accounting
Use this section to configure accounting settings on the Switch.
Update
Period
This is the amount of time in minutes before the Switch sends an update to the accounting
server. This is only valid if you select the
start-stop
option for the
Exec
or
Dot1x
entries.