Command Line Interface4-764Authentication CommandsYou can configure this switch to authenticate users logging into the system formanagement access using local or RADIUS authentication methods. You can alsoenable port-based authentication for network client access using IEEE 802.1X.Authentication Sequenceauthentication loginThis command defines the login authentication method and precedence. Use the noform to restore the default.Syntaxauthentication login {[local] [radius] [tacacs]}no authentication login• local - Use local password.• radius - Use RADIUS server password.• tacacs - Use TACACS server password.Default SettingLocalCommand ModeGlobal ConfigurationCommand Usage• RADIUS uses UDP while TACACS+ uses TCP. UDP only offers best effortdelivery, while TCP offers a connection-oriented transport. Also, note thatRADIUS encrypts only the password in the access-request packet from theclient to the server, while TACACS+ encrypts the entire body of the packet.Table 4-27 Authentication CommandsCommand Group Function PageAuthentication Sequence Defines logon authentication method and precedence 4-76RADIUS Client Configures settings for authentication via a RADIUS server 4-78TACACS+ Client Configures settings for authentication via a TACACS+ server 4-81Port Security Configures secure addresses for a port 4-84Port Authentication Configures host authentication on specific ports using 802.1X 4-85Network Access Configures MAC authentication and dynamic VLAN assignment 4-94Table 4-28 Authentication SequenceCommand Function Mode Pageauthentication login Defines logon authentication method and precedence GC 4-76authentication enable Defines the authentication method and precedence forcommand mode changeGC 4-77