Refer to the Authentication tab to define how user credential validation is conducted on behalf of a Management Access policy. Setting up an authentication scheme by policy allows for policy member credential validation collectively, as opposed to authenticating users individually.
To configure an external authentication resource:
Local | Use this option to enable/disable local authentication mode. Local
authentication uses the local username/password database to
authenticate a user. When disabled, an external authentication
resource is used to validate user access requests. The external
authentication resource could be a dedicated RADIUS or TACACS server.
Note: By default the
local authentication mode is enabled. Disabling local
authentication enables the other parameters on the
screen.
|
RADIUS | If authentication is to be handled by an external RADIUS server,
select one of the following options:
|
AAA Policy | If enabling external RADIUS server authentication, select the AAA
policy to use with the external RADIUS resource. Controllers, service
platforms and access points not using their local RADIUS resource will
need to inter-operate with a RADIUS and LDAP Server (AAA Servers) to
provide user database information and user authentication data. The
AAA policy points to this external RADIUS server resource. Select the Create icon as needed to define a new AAA policy or select the Edit icon to modify the configuration of an existing policy. |
TACACS | If local authentication is disabled, and authentication is to be
handled by an external TACACS server, select one of the following
options:
|
AAA TACACS Policy | If enabling external TACACS server authentication, select the
TACACS policy to use. The AAA TACACS policy points to this external
TACACS server resource. Select an existing AAA TACACS policy (if available), or select Create to define a new policy or Edit to modify an existing one. |