Configuring radius authorization – Brocade BigIron RX Series Configuration Guide User Manual
Page 177
![background image](/manuals/361694/177/background.png)
BigIron RX Series Configuration Guide
99
53-1002484-04
Configuring RADIUS security
3
The commands above cause RADIUS to be the primary authentication method for securing Telnet
access to the CLI. If RADIUS authentication fails due to an error with the server, local authentication
is used instead.
To create an authentication-method list that specifies RADIUS as the primary authentication
method for securing access to Privileged EXEC level and CONFIG levels of the CLI.
BigIron RX(config)# aaa authentication enable default radius local none
The command above causes RADIUS to be the primary authentication method for securing access
to Privileged EXEC level and CONFIG levels of the CLI. If RADIUS authentication fails due to an error
with the server, local authentication is used instead. If local authentication fails, no authentication
is used; the device automatically permits access.
For information on the command syntax, refer to
“Examples of authentication-method lists”
NOTE
For examples of how to define authentication-method lists for types of authentication other than
RADIUS, refer to
“Configuring authentication-method lists”
Entering privileged EXEC mode after a Telnet or SSH login
By default, a user enters User EXEC mode after a successful login through Telnet or SSH. You can
configure the device so that a user enters Privileged EXEC mode after a Telnet or SSH login. To do
this, use the following command.
BigIron RX(config)# aaa authentication login privilege-mode
Syntax: aaa authentication login privilege-mode
The user’s privilege level is based on the privilege level granted during login.
Configuring Enable authentication to prompt for password only
If Enable authentication is configured on the device, by default, a user is prompted for a username
and password. When the user attempts to gain Super User access to the Privileged EXEC and
CONFIG levels of the CLI. You can configure the BigIron RX to prompt only for a password. The
device uses the username (up to 255 characters) entered at login, if one is available. If no
username was entered at login, the device prompts for both username and password.
To configure the BigIron RX to prompt only for a password when a user attempts to gain Super User
access to the Privileged EXEC and CONFIG levels of the CLI.
BigIron RX(config)# aaa authentication enable implicit-user
Syntax: [no] aaa authentication enable implicit-user
Configuring RADIUS authorization
The device supports RADIUS authorization for controlling access to management functions in the
CLI. Two kinds of RADIUS authorization are supported:
•
Exec authorization determines a user’s privilege level when they are authenticated
•
Command authorization consults a RADIUS server to get authorization for commands entered
by the user