Configuring AAA for AOS-CX
Authentication, Authorization, and Accounting (AAAAuthentication, Authorization, and Accounting. AAA is a security framework to authenticate users, authorize the type of access based on user credentials, and record authentication events and information about the network access and network resource consumption.) is a security framework to authenticate users, authorize the type of access based on user credentials, and record authentication events and information about the network access and network resource consumption.
From the Administrator page, you can configure the following AAA properties:
- Authentication using TACACSTerminal Access Controller Access Control System. TACACS is a family of protocols that handles remote authentication and related services for network access control through a centralized server. , RADIUSRemote Authentication Dial-In User Service. An Industry-standard network access protocol for remote authentication. It allows authentication, authorization, and accounting of remote users who want to access network resources. , and local server groups.
- Authorization using TACACS and local server groups.
- Accounting using TACACS, RADIUS, and local server groups.
To configure AAA properties for AOS-CX switches, complete the following steps:
- In the
- To select a switch group in the filter:
- Set the filter to a group.
The dashboard context for the group is displayed.
- Under , click > .
- Click the or icon to view the switch configuration dashboard.
- Set the filter to a group.
- To select a switch in the filter:
- Set the filter to or a group containing at least one switch.
- Under
A list of switches is displayed in the
view. , click > . - Click an AOS-CX switch under .
The dashboard context for the switch is displayed.
- Under
The AOS-CX UI configuration page is displayed.
, click .
app, select one of the following options: - To select a switch group in the filter:
- Click
The Administrator page is displayed with Authentication, Authorization, and Accounting tables.
> . - You can configure Authentication, Authorization and Accounting from the respective tables.
- To configure Authentication, click
Table 1: Authentication Parameters
Name
Description
Value
The type of protocol to enable connection to the server groups for authentication. You can add one or more protocols by clicking
in the Authentication table., , , and .
The list of server groups to be used for authentication. You can select one server group at a time. To add the next server group, click
either in the protocol row or any of the server group rows.The server groups are accessed in the top-down order. You can rearrange the order by dragging the server group to a different position using the
drag-and-drop icon.
, , and .
in the table and configure the following parameters. - To configure Authorization, click
Table 2: Authorization parameters
Name
Description
Value
The type of protocol to enable connection to the server groups for authorization. You can add one or more protocols by clicking
in the Authorization table., , and .
The list of server groups to be used for authorization. You can select one server group at a time. To add the next server group, click
either in the protocol row or any of the server group rows.The server groups are accessed in the top-down order. You can rearrange the order by dragging the server group to a different position using the
drag-and-drop icon.
in the table and configure the following parameters. - To configure Accounting, click
Table 3: Accounting Parameters
Name
Description
Value
The type of protocol to enable connection to the server groups for accounting. You can add one or more protocols by clicking
in the Accounting table., , , and .
The list of server groups to be used for accounting. You can select one server group at a time. To add the next server group, click
either in the protocol row or any of the server group rows.The server groups are accessed in the top-down order. You can rearrange the order by dragging the server group to a different position using the
drag-and-drop icon.
, , and .
in the table and configure the following parameters.
- To configure Authentication, click
- Click .
Deleting AAA properties
To delete Authentication, Authorization, or Accounting, point to the row for the AAA property in the respective tables, and click the delete icon.