
vi BigIron RX Series Configuration Guide
53-1001810-01
Configuring SSL security for the Web Management Interface. . . . . 78
Enabling the SSL server on the device. . . . . . . . . . . . . . . . . . . . 78
Importing digital certificates and RSA private key files. . . . . . . 79
Generating an SSL certificate . . . . . . . . . . . . . . . . . . . . . . . . . . . 79
Configuring TACACS/TACACS+ security . . . . . . . . . . . . . . . . . . . . . . . 80
How TACACS+ differs from TACACS. . . . . . . . . . . . . . . . . . . . . . . 80
TACACS/TACACS+ authentication, authorization, and accounting80
TACACS/TACACS+ configuration considerations . . . . . . . . . . . . 84
Enabling SNMP to configure TACACS/TACACS . . . . . . . . . . . . . . 85
Identifying the TACACS/TACACS+ servers. . . . . . . . . . . . . . . . . . 85
Specifying different servers for individual AAA functions . . . . .86
Setting optional TACACS/TACACS+ parameters. . . . . . . . . . . . . 86
Configuring authentication-method lists for TACACS/TACACS+ 88
Configuring TACACS+ authorization . . . . . . . . . . . . . . . . . . . . . . 89
Configuring TACACS+ accounting . . . . . . . . . . . . . . . . . . . . . . . . 92
Configuring an interface as the source for all TACACS/TACACS+
packets . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 94
Displaying TACACS/TACACS+ statistics and configuration information
95
Configuring RADIUS security . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 96
RADIUS authentication, authorization, and accounting . . . . . .96
RADIUS configuration considerations. . . . . . . . . . . . . . . . . . . . . 99
RADIUS configuration procedure . . . . . . . . . . . . . . . . . . . . . . . . 99
Configuring Brocade-specific attributes on the RADIUS server100
Enabling SNMP to configure RADIUS . . . . . . . . . . . . . . . . . . . .101
Identifying the RADIUS server to the BigIron RX . . . . . . . . . . .101
Specifying different servers for individual AAA functions . . . .102
Setting RADIUS parameters . . . . . . . . . . . . . . . . . . . . . . . . . . .102
Configuring authentication-method lists for RADIUS. . . . . . . .103
Configuring RADIUS authorization . . . . . . . . . . . . . . . . . . . . . .104
Configuring RADIUS accounting . . . . . . . . . . . . . . . . . . . . . . . .106
Configuring an interface as the source for all RADIUS packets107
Displaying RADIUS configuration information . . . . . . . . . . . . .108
Configuring authentication-method lists . . . . . . . . . . . . . . . . . . . . .109
Configuration considerations for authentication-method lists110
Examples of authentication-method lists. . . . . . . . . . . . . . . . .111
Chapter 5 Configuring Basic Parameters
In this chapter . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .113
Entering system administration information . . . . . . . . . . . . . . . . . .114
Configuring Simple Network Management Protocol(SNMP) traps.114
Specifying an SNMP trap receiver . . . . . . . . . . . . . . . . . . . . . .115
Specifying a Single trap source. . . . . . . . . . . . . . . . . . . . . . . . .115
Setting the SNMP Trap holddown time. . . . . . . . . . . . . . . . . . .116
Disabling SNMP traps . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .116
Disabling Syslog messages and traps for CLI access . . . . . . .117
Configuring an interface as the source for all Telnet packets . . . .118
Cancelling an outbound Telnet session . . . . . . . . . . . . . . . . . .119