D-Link DI-3660 [334/506] Tacacs

D-Link DI-3660 [334/506] Tacacs
Command Line Interface Reference Manual
334
The keyword list-name is any character string used to name the list you are creating. The keyword method refers to the
actual method the authentication algorithm tries. The additional methods of authentication are used only if the previous
method returns an error, not if it fails. To specify that the authentication should succeed even if all methods return an error,
specify none as the final method in the command line. For example, to specify that authentication should succeed even if
(in this example) the TACACS+ server returns an error, enter the following command line: 
aaa (default) authentication ppp local
Keyword list-name is to name any string in a created list. Keyword method is to designate the actual method that
is adpoted during the authentication. If only the previous methods return to authentication error, will other methods be
used; If the previous methods return to authentication failure, will there be no more method to authenticate. If you want
to specify that even all methods returned to error can still succesfully carry on the authentication, you should simply
specify none as the last authentication method in the command line. For instance, in the following example, if you want
to ensure the successful authentication even if the TACACSserver returns error, you can input the command line of:
aaa (default) authentication ppp tacacs+ none
Note: Since none allows all users logging in to authenticate successfully, it should be used as a backup method of
authentication.
Following talbe lists the AAA authentication PPP methods:
Keyword Description
group Use a server group to authenticate
group-restrict
Use a server group to authenticate, but when a user has designated a certain server, this
group will be invalidated
local Use the local username database to authenticate
local-case Use the local username database to authenticate(the username is case-sensitive)
none The authentication will pass unconditionedly
radius Use RADIUS authentication
tacacs+ Use TACACS+ authentication
n PPP Authentication Using Local Password
In aaa authentication ppp command, the keyword local is used to designate to authenticate with a local
username database. For instance, if you want to designate the local username databse as the
authentication method on a PPP line without using other methods, you can input the following conmmand
line:
aaa (default) authentication ppp local
For information about adding users into the local username database, see the “Establish Local
AuthenticationDatabasesection in this chapter.
n PPP Authentication Using RADIUS
In aaa authentication ppp command, the keyword RADIUS is used to designate RADIUS to authenticate.
For instance, if you want to designate the local username databse as the authentication method on a PPP
line without using other methods, you can input the following conmmand line:
aaa (default) authentication ppp radius

Содержание

Скачать