
4. Select Save.
5. Edit the existing groups or users in TACACS to use the AMP service and define a role for the group or user.
l The role defined on the Group Setup page in ACS must match the exact name of the role defined on the AMP
Setup > Roles page.
n The defined role should use the following format: role=<name_of_AMP_role>. One example is as follows:
role=DormMonitoring
As with routers and switches, AirWave does not need to know usernames.
6. AirWave also needs to be configured as an AAA client.
l On the Network Configuration page, select Add Entry.
l Enter the IP address of AirWave as the AAA Client IP Address.
l The secret should be the same value that was entered on the AMP Setup > TACACS+ page.
7. Select TACACS+ (Cisco IOS) in the Authenticate Using drop down menu and select submit + restart.
AirWave checks the local username and password store before checking with the TACACS+ server. If the user is found
locally, the local password and local role apply. When using TACAS+, it is not necessary or recommended to define users
on the AirWave server. The only recommended user is the backup administrator, in the event that the TACAS+ server goes
down.
Configuring LDAP Authentication and Authorization
LDAP (Lightweight Directory Access Protocol) provides users with a way of accessing and maintaining distributed
directory information services over a network. When LDAP is enabled, a client can begin a session by authenticating
against an LDAP server which by default is on TCP port 389.
Perform these steps to configure LDAP authentication:
1. Go to the AMP Setup> Authentication page.
2. Select the Yes radio button to enable LDAP authentication and authorization. Once enabled, the available LDAP
configuration options will display. Figure 26 illustrates this page.
Dell Networking W-AirWave 8.0 | User Guide Configuring AirWave | 55
Kommentare zu diesen Handbüchern