Quick Reference Guide

xxiv PowerConnect B-Series TI24X Configuration Guide
53-1002269-02
Restricting remote access to management functions . . . . . . . . . .857
Using ACLs to restrict remote access . . . . . . . . . . . . . . . . . . . .857
Defining the console idle time . . . . . . . . . . . . . . . . . . . . . . . . .859
Restricting remote access to the device to specific IP addresses860
Restricting access to the device based on IP or
MAC address . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .861
Specifying the maximum number of login attempts
for Telnet access . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .861
Restricting remote access to the device to specific
VLAN IDs . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .862
Designated VLAN for Telnet management sessions to a Layer 2
Switch . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .863
Device management security . . . . . . . . . . . . . . . . . . . . . . . . . .863
Disabling specific access methods. . . . . . . . . . . . . . . . . . . . . .864
Setting passwords. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .865
Setting a Telnet password . . . . . . . . . . . . . . . . . . . . . . . . . . . . .866
Setting passwords for management privilege levels. . . . . . . .866
Recovering from a lost password . . . . . . . . . . . . . . . . . . . . . . .868
Displaying the SNMP community string . . . . . . . . . . . . . . . . . .869
Disabling password encryption . . . . . . . . . . . . . . . . . . . . . . . . .869
Specifying a minimum password length. . . . . . . . . . . . . . . . . .869
Setting up local user accounts. . . . . . . . . . . . . . . . . . . . . . . . . . . . .870
Enhancements to username and password . . . . . . . . . . . . . .870
Configuring a local user account . . . . . . . . . . . . . . . . . . . . . . . 874
Create password option. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 876
Changing a local user password . . . . . . . . . . . . . . . . . . . . . . . .876
Configuring TACACS/TACACS+ security . . . . . . . . . . . . . . . . . . . . . .877
How TACACS+ differs from TACACS. . . . . . . . . . . . . . . . . . . . . .877
TACACS/TACACS+ authentication, authorization,
and accounting . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .877
TACACS authentication . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .878
TACACS/TACACS+ configuration considerations . . . . . . . . . . .881
Enabling TACACS . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .881
Identifying the TACACS/TACACS+ servers. . . . . . . . . . . . . . . . .882
Specifying different servers for individual AAA functions . . . .883
Setting optional TACACS/TACACS+ parameters. . . . . . . . . . . .883
Configuring authentication-method lists for TACACS/TACACS+884
Configuring TACACS+ authorization . . . . . . . . . . . . . . . . . . . . .886
Configuring TACACS+ accounting . . . . . . . . . . . . . . . . . . . . . . .889
Configuring an interface as the source for all
TACACS/TACACS+ packets. . . . . . . . . . . . . . . . . . . . . . . . . . . . .891
Displaying TACACS/TACACS+ statistics and
configuration information . . . . . . . . . . . . . . . . . . . . . . . . . . . . .891