Users close
External Authentication
Enable External Authentication: External Authentication is used for authenticating external users, i.e. users that are not in the device's local user database and part of a configured server (such as a RADIUS server). Select this option to enable/disable external users to login to this device. Select Yes to allow the external users to login, and select No to disable the external user login access.

Click Apply to save the settings.
Click Reset to discard any changes and revert to the previous settings.

RADIUS Server Configuration
The RADIUS server is a database of user accounts, typically used in larger environments. If a RADIUS server already exists, it can be used for authenticating users that want to connect to this device. The RADIUS client first attempts to authenticate with the primary server (mandatory) and can attempt connecting to a backup server if authentication fails.

Primary Server Address: The IP address of the primary RADIUS server.

Secret Phrase: The RADIUS server and client (this router) authenticate to each other with the use of a shared phrase. Enter the secret phrase (password) as configured on the RADIUS server for this router (client).

Primary Server NAS Identifier: A NAS (Network Access Server) identifier MUST be present in a RADIUS request. Ensure that the same NAS identifier is configured on both the client (this router) and server.

Authentication Type: Choose the authentication type for this particular domain. Options are: Radius-PAP, Radius-CHAP, WIKID-PAP, WIKID-CHAP, MIAS-PAP and MIAS-CHAP.

Radius-PAP/CHAP: These types of authentication mechanisms are used with RADIUS Server.

WIKID-PAP/CHAP: This type of authentication requires authentication token valid only for one session;
contact your administrator for the token if configuring WIKID authentication for this domain.

MIAS-PAP/CHAP: This type of authentication requires a password;
contact your administrator for this secret if configuring MIAS authentication for this domain.

Enable Backup RADIUS Server: Check this box to enable a backup RADIUS server, to be used in the event that connection or authentication with the primary RADIUS server fails.

Backup Server Address: The IP address of the backup RADIUS server.

Secret Phrase: The RADIUS server and client (this router) authenticate to each other with the use of a shared phrase. Enter the secret phrase (password) as configured on the RADIUS server for this router (client).

Backup Server NAS Identifier:
A NAS (Network Access Server) identifier MUST be present in a RADIUS request. Ensure that the same NAS identifier is configured on both the client (this router) and server.

Authentication Settings
Domain Name: The user can configure the domain name to display for authentication with an external domain. This will be displayed in the login page.

Retry Time out: Set the amount of time in seconds, the router should wait for a response from the RADIUS server before timing out the authentication attempt.

Maximum Retry Count: This determines the number of tries the router will make to the RADIUS server before giving up and failing the authentication attempt.

Users Default Timeout: The session idle timeout for the user.
Click Apply to save the settings.
Click Reset to revert to the previous settings.
 

2010 © Copyright NETGEAR®

close