162 Security
Notes
•
The external user and password information is transmitted as plain text during
RADIUS login. Use HTTPS login as an alternative to HTTP.
•
The local logins does not perform hashing of the password in external RADIUS login.
Hence, HTTPS / TLS encryption is used for password encryption.
•
Local user accounts can be left active on side of the external RADIUS user accounts.
Local accounts should have strong passwords. In cases when RADIUS server is
unreachable (e.g. due to lost network connection), local login will be enabled once per
failed RADIUS login even if the local logins are disabled.
Protocol level implementation for RADIUS
On protocol level, NETA-21 sends a RADIUS access request to RADIUS server with
attributes as follows:
Attribute name
Attribute ID
Value
Vendor-ID
56
“ABB” (ID 100)
Vendor-Sub-Type
57
“Drives” (ID 101)
NETA-21 module
Web browser
(HTML / Javascript)
Login dialog
HTTPS frontend
(HTTP not
recommended)
Username,
Password,
Auth.method
(as plaintext)
Over HTTPS
Lo
cal
D
B
(se
tti
n
g
s,
RA
D
IU
S
se
rv
e
r
se
tu
p
,
al
lo
w
e
d
R
A
D
IU
S
u
se
r
na
me
fi
lt
e
r)
Us
e
r
acco
u
n
ts
RADIUS
authentication
server in
network
DataHub with
internal settings
and local user
accounts
RADIUS-protocol
Basic (RFC2865)
EAP-TTLS (RFC581)
Summary of Contents for NETA-21
Page 2: ......
Page 4: ......
Page 18: ...18 Introduction to the manual ...
Page 32: ...32 Electrical installation ...
Page 42: ...42 Start up ...
Page 50: ...50 Program features ...
Page 56: ...56 Front page ...
Page 68: ...68 Users ...
Page 114: ...114 Networks ...
Page 150: ...150 Reporting ...
Page 172: ...172 Security ...
Page 176: ...176 Memory card ...
Page 184: ...184 Frequently asked questions ...
Page 190: ...190 Diagnostics and troubleshooting ...
Page 194: ...194 Technical data ...