Section 3 managing fabrics, 1 radius servers, Section 3 – Sun Microsystems 5602 User Manual

Page 47: Managing fabrics, Radius servers -1, Describ, Radius servers

Advertising
background image

59097-01 A

3-1

Section 3

Managing Fabrics

This section describes the following tasks that manage fabrics:

„

RADIUS Servers

„

Securing a Fabric

„

Tracking Fabric Firmware and Software Versions

„

Managing the Fabric Database

„

Displaying Fabric Information

„

Working with Device Information and Nicknames

„

Zoning a Fabric

3.1

RADIUS Servers

Remote Authentication Dial In User Service (RADIUS) provides a method to
centralize the management of authentication passwords in larger networks. It has
a client/server model, where the server is the password repository and third party
authentication point and the clients are all of the managed devices. RADIUS can
be configured for devices and/or user accounts. The RADIUS server dialogs are
available only on a secure (SSL) fabric and on the entry switch (out of band
switch). Refer to

”Connection Security” on page 3-7

and

”System Services Dialog”

on page 4-25

for more information.

RADIUS is designed to authenticate users and devices using a
challenge/response protocol. Basic implementations consist of a central RADIUS
server containing a database of authorized users as well as authentication
information. A RADIUS client wishing to verify the authenticity of a user issues a
challenge to the user and collects the response to the challenge. This information
is forwarded to the RADIUS server for authentication and the server responds
with the results, either an accept or reject. The RADIUS client does not need to be
configured with any user authentication information, this all resides on the
RADIUS server and can be managed centrally and separately from the clients. In
addition, no passwords are exchanged between the RADIUS server and its
clients. Authentication of requests from a RADIUS client to the server and
responses from the server to a client can also be authenticated. This requires
sharing a secret between the server and client. The accounting RADIUS supports
the auditing of the users and switch services such as Telnet, FTP, and switch
management applications.

Advertising