3Com 4500 Switch User Manual


 
i
Table of Contents
1 AAA Overview············································································································································1-1
Introduction to AAA ·································································································································1-1
Authentication··································································································································1-1
Authorization····································································································································1-1
Accounting·······································································································································1-1
Introduction to ISP Domain ·············································································································1-2
Introduction to AAA Services ··················································································································1-2
Introduction to RADIUS···················································································································1-2
2 AAA Configuration ····································································································································2-1
AAA Configuration Task List ···················································································································2-1
Creating an ISP Domain and Configuring Its Attributes··································································2-2
Configuring an AAA Scheme for an ISP Domain············································································2-3
Configuring Dynamic VLAN Assignment·························································································2-5
Configuring the Attributes of a Local User·······················································································2-6
Cutting Down User Connections Forcibly························································································2-8
RADIUS Configuration Task List·············································································································2-8
Creating a RADIUS Scheme·········································································································2-10
Configuring RADIUS Authentication/Authorization Servers··························································2-10
Configuring RADIUS Accounting Servers ·····················································································2-11
Configuring Shared Keys for RADIUS Messages·········································································2-12
Configuring the Maximum Number of RADIUS Request Transmission Attempts·························2-13
Configuring the Type of RADIUS Servers to be Supported ··························································2-13
Configuring the Status of RADIUS Servers···················································································2-14
Configuring the Attributes of Data to be Sent to RADIUS Servers ···············································2-15
Configuring the Local RADIUS Server ··························································································2-16
Configuring Timers for RADIUS Servers·······················································································2-17
Enabling Sending Trap Message when a RADIUS Server Goes Down ·······································2-18
Enabling the User Re-Authentication at Restart Function·····························································2-18
Displaying and Maintaining AAA Configuration ····················································································2-20
Displaying and Maintaining AAA Configuration·············································································2-20
Displaying and Maintaining RADIUS Protocol Configuration························································2-20
AAA Configuration Examples················································································································2-20
Remote RADIUS Authentication of Telnet/SSH Users ·································································2-20
Local Authentication of FTP/Telnet Users·····················································································2-22
Troubleshooting AAA ····························································································································2-23
Troubleshooting RADIUS Configuration························································································2-23
3 EAD Configuration···································································································································3-24
Introduction to EAD·······························································································································3-24
Typical Network Application of EAD ·····································································································3-24
EAD Configuration ································································································································3-25
EAD Configuration Example ·················································································································3-25