
C-2 TACACS+ Authentication Example
LX Series Configuration Guide
The TACACS+ superuser request attribute is independent from
the TACACS+ login. The TACACS+ superuser request attribute
is used to indicate which database to authenticate the superuser
password against after a user is logged in. When a user types
the enable command, and the TACACS+ superuser request is
enabled, the enable password will be authenticated against the
TACACS+ server database; otherwise it is checked against the
LX database "system".
TACACS+ Authentication Example
The following example describes the steps in the TACACS+
authentication process. In this example, the user attempts to
gain access to an LX asynchronous port.
1. The LX unit prompts the user for a username and password.
2. The username is sent to the TACACS+ authentication start
packet.
3. The server responds with an authentication reply packet,
which will either allow the user access or require a
password.
4. If a password is required, the user is prompted for one and
the LX sends it to the server in an authentication continue
packet.
5. The server responds with a packet that contains an
authentication status pass or an authentication status fail.
6. If the request is successful, the user will be allowed to log in;
otherwise the user will have two more chances to receive an
authentication status pass back from the server.
7. The LX unit then grants the user the services requested.
Komentarze do niniejszej Instrukcji