vi BigIron RX Series Configuration Guide
53-1001986-01
Configuring SSL security for the Web Management Interface. . . . .82
Enabling the SSL server on the device. . . . . . . . . . . . . . . . . . . . 83
Importing digital certificates and RSA private key files. . . . . . .83
Generating an SSL certificate . . . . . . . . . . . . . . . . . . . . . . . . . . .84
Configuring TACACS and TACACS+ security . . . . . . . . . . . . . . . . . . . . 84
How TACACS+ differs from TACACS . . . . . . . . . . . . . . . . . . . . . . .84
TACACS and TACACS+ authentication, authorization,
and accounting . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 85
TACACS and TACACS+ configuration considerations . . . . . . . . .88
Enabling SNMP to configure TACACS and TACACS. . . . . . . . . . .89
Identifying the TACACS and TACACS+ servers . . . . . . . . . . . . . .89
Specifying different servers for individual AAA functions . . . . .90
Setting optional TACACS and TACACS+ parameters . . . . . . . . . 90
Configuring authentication-method lists for TACACS
and TACACS+ . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .92
Configuring TACACS+ authorization . . . . . . . . . . . . . . . . . . . . . . 94
Configuring TACACS+ accounting . . . . . . . . . . . . . . . . . . . . . . . . 97
Configuring an interface as the source for all TACACS
and TACACS+ packets . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .98
Displaying TACACS and TACACS+ statistics and
configuration information . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .98
Configuring RADIUS security . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .100
RADIUS authentication, authorization, and accounting . . . . .100
RADIUS configuration considerations. . . . . . . . . . . . . . . . . . . .103
RADIUS configuration procedure . . . . . . . . . . . . . . . . . . . . . . .103
Configuring Brocade-specific attributes on the
RADIUS server . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .104
Enabling SNMP to configure RADIUS . . . . . . . . . . . . . . . . . . . .105
Identifying the RADIUS server to the BigIron RX . . . . . . . . . . .105
Specifying different servers for individual AAA functions . . . .106
Setting RADIUS parameters . . . . . . . . . . . . . . . . . . . . . . . . . . .106
Configuring authentication-method lists for RADIUS. . . . . . . . 107
Configuring RADIUS authorization . . . . . . . . . . . . . . . . . . . . . .108
Configuring RADIUS accounting . . . . . . . . . . . . . . . . . . . . . . . .110
Configuring an interface as the source for all RADIUS
packets . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .111
Displaying RADIUS configuration information . . . . . . . . . . . . .112
Configuring authentication-method lists . . . . . . . . . . . . . . . . . . . . .113
Configuration considerations for authentication-
method lists . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .114
Examples of authentication-method lists. . . . . . . . . . . . . . . . .115
Chapter 5 Configuring Basic Parameters
Entering system administration information. . . . . . . . . . . . . . . . . . 117
Configuring Simple Network Management Protocol traps . . . . . . .118
Specifying an SNMP trap receiver . . . . . . . . . . . . . . . . . . . . . .118
Specifying a Single trap source. . . . . . . . . . . . . . . . . . . . . . . . .119
Setting the SNMP Trap holddown time. . . . . . . . . . . . . . . . . . .119
Disabling SNMP traps . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .120
Disabling Syslog messages and traps for CLI access . . . . . . .121