Cisco Systems OL-27172-01 Mobility Aid User Manual


 
13-19
Cisco Broadband Access Center 3.8 Administrator Guide
OL-27172-01
Chapter 13 Configuring CWMP Service Security
Configuring Security for RDU Services
You can select one of the authentication modes by using the administrator user interface. Local
authentication option is the default.
RDU Authentication Mode Settings
You can select either local or TACACS+ authentication by using the administrator user interface. To
enable TACACS+ authentication:
Step 1 Choose Configuration on either the Primary Navigation bar or Main Menu page.
Step 2 Choose Defaults from the Secondary Navigation bar.
The Configure Defaults page appears.
Step 3 Click TACACS+ Defaults link on the left pane.
The TACACS+ Defaults page appears.
Step 4 Check the TACACS+ Authentication check box.
Step 5 Set the TACACS+ server and encryption key.
You can specify up to maximum of 5 TACACS+ servers. The order of the entries determines the order
in which the TACACS+ servers are tried.
Step 6 Set the TACACS+ Client Read/Write timeout.
This is the time that the TACACS+ client waits for a TACACS+ server to reply to TACACS+ protocol
requests. The range is from 1 to 300 seconds. The default is 5 seconds and applies to all TACACS+
servers.
Step 7 Set the TACACS+ Client Maximum retries.
This is the number of times that the TACACS+ client attempts a valid TACACS+ protocol exchange with
a TACACS+ server if it fails to respond to initial request. The range is from 0 to 10. The default is 1 and
applies to all TACACS+ server defined.
Step 8 Click Submit.
TACACS+ Authentication and Authorization in RDU
When TACACS+ authentication is enabled, the client attempts user login authentication to each server
sequentially in the list until a successful authentication exchange is executed, or the list is exhausted. If
the list is exhausted, the client automatically falls back into the local authentication mode (using the
local system password).
After the TACACS+ authentication is done, the user authorization (i.e, user role as Admin, read-write
user or read-only user) is retrieved from the RDU database. You can specify the user role (read-write or
a read-only) in the Add Users page in the administrator user interface.