D-Link DGS-3100 Switch User Manual


 
DGS-3100 Series Gigabit Stackable Managed Switch CLI Manual
18
3
create authen_login method_list_name
Purpose To create a user-defined list of authentication methods for users
logging on to the Switch.
Syntax
create authen_login method_list_name <string 12>
Description The create authen_login method_list_name command creates a
list of authentication techniques for user login. The Switch can
support up to eight method lists, but one is reserved as a default and
cannot be deleted. Multiple method lists must be created and
configured separately.
Parameters <string 12> - Defines the method_list_name to be created as a string
of up to 12 alphanumeric characters.
Restrictions Only Administrator or operator-level users can issue this command.
Example usage:
To create the method list ‘Trinity’:
DGS3100# create authen_login method_list_name Trinity
Success.
DGS3100#
config authen_login
Purpose To configure a user-defined or default method list of authentication
methods for user login.
Syntax
config authen_login [default | method_list_name <string 12>|
http_method_list | https_method_list] method {tacacs+ | radius
| local | none}
Description The config authen_login command configures a user-defined or
default method list of authentication methods for users logging on to
the Switch. The sequence of methods implemented in this command
affects the authentication result. For example, if a user enters a
sequence of methods like tacacs – local, the Switch sends an
authentication request to the first tacacs host in the server group. If
no response comes from the server host, the Switch sends an
authentication request to the second tacacs host in the server group
and so on, until the list is exhausted. When the local method is used,
the privilege level is dependant on the local account privilege
configured on the Switch.
Successful login using any of these methods gives the user a ‘user’
priviledge only. If the user wishes to upgrade his or her status to the
administrator level, the user must implement the enable admin
command, followed by a previously configured password. (See the
enable admin part of this section for more detailed information,
concerning the enable admin command.)
Parameters default – The default method list for access authentication, as
defined by the user. The user may choose one or more of the
following authentication methods:
tacacs+ – Specifies that the user is to be authenticated
using the TACACS+ protocol from the remote TACACS+
server hosts of the TACACS+ server group list.