User's Manual

Contents
x
Catalyst 3750 Switch Software Configuration Guide
OL-8550-09
Change-of-Authorization Requests 9-21
CoA Request Response Code 9-22
CoA Request Commands 9-23
Stacking Guidelines for Session Termination 9-26
Configuring RADIUS 9-27
Default RADIUS Configuration 9-27
Identifying the RADIUS Server Host 9-28
Configuring RADIUS Login Authentication 9-30
Defining AAA Server Groups 9-32
Configuring RADIUS Authorization for User Privileged Access and Network Services 9-34
Starting RADIUS Accounting 9-35
Establishing a Session with a Router if the AAA Server is Unreachable 9-36
Configuring Settings for All RADIUS Servers 9-36
Configuring the Switch to Use Vendor-Specific RADIUS Attributes 9-36
Configuring the Switch for Vendor-Proprietary RADIUS Server Communication 9-38
Configuring CoA on the Switch 9-39
Monitoring and Troubleshooting CoA Functionality 9-40
Configuring RADIUS Server Load Balancing 9-40
Displaying the RADIUS Configuration 9-40
Controlling Switch Access with Kerberos 9-40
Understanding Kerberos 9-41
Kerberos Operation 9-43
Authenticating to a Boundary Switch 9-43
Obtaining a TGT from a KDC 9-43
Authenticating to Network Services 9-44
Configuring Kerberos 9-44
Configuring the Switch for Local Authentication and Authorization 9-44
Configuring the Switch for Secure Shell 9-45
Understanding SSH 9-46
SSH Servers, Integrated Clients, and Supported Versions 9-46
Limitations 9-47
Configuring SSH 9-47
Configuration Guidelines 9-47
Setting Up the Switch to Run SSH 9-48
Configuring the SSH Server 9-49
Displaying the SSH Configuration and Status 9-50
Configuring the Switch for Secure Socket Layer HTTP 9-50
Understanding Secure HTTP Servers and Clients 9-51
Certificate Authority Trustpoints 9-51