Authentication login – Microsens MS453490M Management Guide User Manual

Page 587

Advertising
background image

C

HAPTER

24

| Authentication Commands

Authentication Sequence

– 587 –

E

XAMPLE

Console(config)#authentication enable radius

Console(config)#

R

ELATED

C

OMMANDS

enable password

- sets the password for changing command modes (

584

)

authentication login

This command defines the login authentication method and precedence.

Use the no form to restore the default.

S

YNTAX

authentication login {[local] [radius] [tacacs]}
no authentication login

local - Use local password.
radius - Use RADIUS server password.
tacacs - Use TACACS server password.

D

EFAULT

S

ETTING

Local

C

OMMAND

M

ODE

Global Configuration

C

OMMAND

U

SAGE

RADIUS uses UDP while TACACS+ uses TCP. UDP only offers best effort

delivery, while TCP offers a connection-oriented transport. Also, note

that RADIUS encrypts only the password in the access-request packet

from the client to the server, while TACACS+ encrypts the entire body

of the packet.

RADIUS and TACACS+ logon authentication assigns a specific privilege

level for each user name and password pair. The user name, password,

and privilege level must be configured on the authentication server.

You can specify three authentication methods in a single command to

indicate the authentication sequence. For example, if you enter

authentication login radius tacacs local,” the user name and

password on the RADIUS server is verified first. If the RADIUS server is

not available, then authentication is attempted on the TACACS+ server.

If the TACACS+ server is not available, the local user name and

password is checked.

E

XAMPLE

Console(config)#authentication login radius

Console(config)#

Advertising