Users |
 |
|
External Authentication |
Enable External Authentication: External
Authentication is used for authenticating external users, i.e. users that are
not in the device's local user database and part of a configured server (such as
a RADIUS server). Select this option to enable/disable external users to login
to this device. Select
Yes to allow the external users to login, and select
No
to disable the external user login access.
Click
Apply to save the settings.
Click
Reset to discard any changes and revert to the
previous settings.
RADIUS Server Configuration
The
RADIUS server is a database of user accounts,
typically used in larger environments. If a
RADIUS server already exists, it can
be used for authenticating users that want to connect to this device. The
RADIUS
client first attempts to authenticate with the primary server (mandatory) and
can attempt connecting to a backup server if authentication fails.
Primary Server Address: The IP address of the
primary RADIUS server.
Secret Phrase: The
RADIUS server and client (this
router) authenticate to each other with the use of a shared phrase. Enter the
secret phrase (password) as configured on the
RADIUS server for this router (client).
Primary Server NAS Identifier: A NAS (Network Access Server) identifier MUST be
present in a RADIUS request. Ensure that the same NAS identifier is configured
on both the client (this router) and server.
Authentication Type: Choose the authentication type
for this particular domain. Options are: Radius-PAP, Radius-CHAP, WIKID-PAP,
WIKID-CHAP, MIAS-PAP and MIAS-CHAP.
Radius-PAP/CHAP: These types of authentication
mechanisms are used with RADIUS Server.
WIKID-PAP/CHAP: This type of authentication
requires authentication token valid only for one session;
contact your administrator for the token if configuring WIKID authentication for
this domain.
MIAS-PAP/CHAP: This type of authentication requires
a password;
contact your administrator for this secret if configuring MIAS authentication
for this domain.
Enable Backup RADIUS Server: Check this box to
enable a backup RADIUS server, to be used in the event that connection or
authentication with the primary RADIUS server fails.
Backup Server Address: The IP address of the backup
RADIUS server.
Secret Phrase: The RADIUS server and client (this router) authenticate to each
other with the use of a shared phrase. Enter the secret phrase (password) as
configured on the
RADIUS server for this router (client).
Backup Server NAS Identifier: A NAS (Network Access Server) identifier MUST be
present in a RADIUS request. Ensure that the same NAS identifier is configured
on both the client (this router) and server.
Authentication Settings
Domain Name: The user can configure the domain name
to display for authentication with an external domain. This will be displayed in
the login page.
Retry Time out: Set the amount of time in seconds,
the router should wait for a response from the
RADIUS server before timing out
the authentication attempt.
Maximum Retry Count: This determines the number of
tries the router will make to the
RADIUS server before giving up and failing the
authentication attempt.
Users Default Timeout: The session idle timeout for
the user. |
Click
Apply to save the settings.
Click
Reset to revert to the previous settings. |
|
|