R3204P16-HP Load Balancing Module Security Configuration Guide-6PW101
160
Level switching authentication for Telnet users by a RADIUS
server
NOTE:
The RADIUS server in this example runs ACSv4.0.
Network requirements
As shown in Figure 119,
• Configure the LB module to use local authentication for the Telnet user and assign the privilege level
of 0 for the user to enjoy after login.
• Configure the LB module to use the RADIUS server and, if RADIUS authentication is not available,
use local authentication instead for level switching authentication of the Telnet user.
Figure 119 Configure RADIUS authentication for level switching users
Configuration considerations
1. Configure the LB module to use AAA, particularly, local authentication for Telnet user
authentication.
• Create ISP domain bbb and configure it to use local authentication for Telnet users.
• Create a local user account, configure the password, and assign the privilege level for the user to
enjoy after login.
2. On the LB module, configure the authentication method for user privilege level switching.
• Specify to use RADIUS authentication and, if RADIUS authentication is not available, use local
authentication for users switching from a lower level to a higher level.
• Configure RADIUS scheme rad and assign an IP address to the RADIUS server. Set the shared keys
for message exchange and specify that usernames sent to the RADIUS server carry no domain
name. Configure the domain to use RADIUS scheme rad for user privilege level switching
authentication.
• Configure the password for local user privilege level switching authentication.
• Add the username and password for user privilege level switching authentication.
3. On the RADIUS server, add the username and password for user privilege level switching
authentication.