Configuring a Local User Database

The following steps configure a local user database and selects username-password as the web authentication mode.

  1. Enter the global configuration mode.
    device# configure terminal
  2. Create a local user database.
    device(config)# local-userdb userdb1
    
    The FastIron switch supports a maximum of ten local user databases, each containing up to 50 user records. Each user record consists of a username and password.
  3. Add user records to the local user database using one of the following methods:
    Note: The colon character is not allowed in usernames.
    • Enter a user record that consists of username and password.
      device(config-localuserdb-userdb1)# username marcia password bunch4
    • Import ASCII text file of user records from the TFTP server.
      device(config-localuserdb-userdb1)# import-users tftp 192.168.1.1 filename userdb1
    The no username command deletes a user record from the local user database. To delete all user records, enter the delete-all command.
    The text file to be imported must be in the following ASCII format.
    [delete-all]
    [no] username 
    username1
     password 
    password1
     cr
    [no] username 
    username2
     password 
    password2
     cr
    ...
    

    The [delete-all] keyword indicates that the user records in the text file will replace the user records in the specified local user database on the FastIron switch. If the [delete-all] keyword is not present, the new user records will be added to the specified local user database on the FastIron switch. The [delete-all] keyword is optional. If present, it must appear on the first line, before the first user record in the text file. The optional [no] keyword indicates that the user entry will be deleted from the specified local user database on the FastIron switch. User records that already exist in the local user database will be updated with the information in the text file when it is uploaded to the switch. Insert a cursor return (cr ) after each user record.

  4. Enable the username-password authentication mode.
    device(config-vlan-10-webauth)# auth-mode username-password
    Complete the configuration steps described in Configuring Web Authentication before this configuration.
  5. Set one of the following authentication methods.
    By default, Web Authentication uses a RADIUS server to authenticate usernames and passwords of the hosts, unless the device is configured to use the local user database.
    • Configure the switch to use a local user database to authenticate users in a VLAN.
      device(config-vlan-10-webauth)# auth-mode username-password auth-methods local
      
    • To revert back to using the RADIUS server, enter the following command.
      device(config-vlan-10-webauth)# auth-mode username-password auth-methods radius
      
  6. If desired, set the authentication method (RADIUS or local) failover sequence.
    device(config-vlan-10-webauth)# auth-mode username-password auth-methods local radius
    

    You can specify a failover sequence for the RADIUS and local user database authentication methods. In this example, Web Authentication is configured to first use a local user database to authenticate users in a VLAN. If the local user database is not available, it will use a RADIUS server. You can specify radius local or local radius depending on the failover sequence desired.

  7. Assign a local user database to a Web Authentication VLAN.
    After creating or importing a local user database on the device and setting the local user database authentication method to local, you can configure a Web Authentication VLAN to use the database to authenticate users in a VLAN.
    device(config-vlan-10-webauth)# auth-mode username-password local-user-database userdb1