Switch Settings: AAA
From the RUCKUS One web interface, you can configure a RADIUS server, TACACS+ server, and Local Users for a switch.
You must configure RADIUS server, TACACS+ server, and Local Users
in order to support authentication, authorization, and accounting processes on RUCKUS
One managed ICX switches associated with a specific venue.
-
In the
Dashboard, click Venues.
Alternatively, on the navigation bar, click Venues.
The Venues page is displayed.
-
Select the Venue
Name and click Edit.
Alternatively, select the Venue Name and click Configure.
The Venue Details page is displayed.
-
Select the Switch
Configuration > AAA.
The AAA tab is displayed.
-
Click Servers and
Users to configure a RADIUS server, TACACS+ server, and Local
Users.
-
Select a specific RADIUS
Server from the table to edit, or add a RADIUS Server.
- Click Add RADIUS Server to add a new RADIUS Server. The Add RADIUS Server sidebar is displayed.
- Complete the
following fields:
- Name: Enter the RADIUS server name.
- IP Address: Enter an IP address for the RADIUS server.
- Authentication Port: Enter a port number for authentication.
- Accounting Port: Enter a port number for accounting.
- Shared Secret: Enter the shared secret.
- Click Save.
-
Select a specific
TACACS+ Server from the table to edit or add a TACACS+ Server.
- Click Add TACACS+ Server to add a new TACACS+ Server. The Add TACACS+ Server sidebar is displayed.
- Complete the
following fields:
- Name: Enter the TACACS+ server name.
- IP Address: Enter an IP address for the TACACS+ server.
- Authentication Port: Enter a port number for authentication.
- Shared Secret: Enter the shared secret.
- Purpose: Select Default (All), Authentication, Authorization, or Accounting. By default, Default (All) is selected.
- Click Save.
-
Select a specific Local
Users from the table to edit or add Local Users.
- Click Add Local User. The Add Local User sidebar is displayed.
- Complete the
following fields:
- User Name: Enter a local user name.
- Password: Enter the password for the local user.
- Privilege: Select Port Config, Read Only, or Read Write.
- Click Save.
- Select a username
to view or edit the associated password, or display information
on how many switches use this password.Note: The Use In column displays information on the total number of switches in the venue and the total number of switches that use the password.
- (Optional) Click Edit to display the Edit Local User sidebar and edit the password; click Save to save the new password.
-
Select a specific RADIUS
Server from the table to edit, or add a RADIUS Server.
-
Click
Settings, or scroll down to the
Settings section, to configure Log-in
Authentication, Authorization, and
Accounting settings.
-
Configure the Log-in
Authentication settings.
- Complete
following fields:
- SSH Authentication: By default, it is switched ON.
- Telnet Authentication: Toggle the switch to ON.
- Set Priority: Select the priority and move them to Available Servers & Users or Selected order table.
- Complete
following fields:
-
Configure the
Authorization settings.
- Complete
following fields:
- Command Authorization: Toggle the
switch to ON and complete the
following fields:
- Level: Select Port Config, Read Only, or Read Write.
- Set Priority: Select the priority and move them to Available Servers or Selected order table.
- Executive Authorization: Toggle the
switch to ON and complete the
following fields:
- Set Priority: Select the priority and move them to Available Servers or Selected order table.
- Command Authorization: Toggle the
switch to ON and complete the
following fields:
- Complete
following fields:
-
Configure the
Accounting.
- Complete
following fields:
- Command Authorization: Toggle the
switch to ON and complete the
following fields:
- Level: Select Port Config, Read Only, or Read Write.
- Set Priority: Select the priority and move them to Available Servers or Selected order table.
- Executive Authorization: Toggle the
switch to ON and complete the
following fields:
- Set Priority: Select the priority and move them to Available Servers or Selected order table.
- Command Authorization: Toggle the
switch to ON and complete the
following fields:
- Complete
following fields:
-
Configure the Log-in
Authentication settings.
- Click Save AAA.