![Asentria Teleboss 850 User Manual Download Page 109](http://html.mh-extra.com/html/asentria/teleboss-850/teleboss-850_user-manual_2981745109.webp)
TeleBoss 850 2.06.280_STD User Manual
Page 103
Locking yourself out
Be careful when you are configuring RADIUS, you may lock yourself out of the unit, which means there is no way to
gain access to the unit again: you must return it in order for it to be reinitialized at the factory. There are four ways
around this:
1. If you are locked out because there is something wrong with the primary RADIUS server (i.e., it is
reachable but it is incorrectly rejecting authentication requests), then configure a secondary (redundant)
one, if you have the resources for that.
2. The unit attempts to detect an invalid RADIUS configuration, and if it finds it, it automatically authenticates
you using User Profiles. An invalid RADIUS configuration is one where (primary server or secret is not
configured) and (secondary server or secret is not configured). So if you have misconfigured the unit in
this way, you can still get into the unit provided you know the credentials for a MASTER-rights user profile.
3. Configure the unit to fall back to User Profiles (
sec.radius.fallback.mode
=USER PROFILES
). This
means when all RADIUS servers configured are unreachable or reachable but unresponsive, the unit will
authenticate and authorize the user with its User Profiles configuration. If any RADIUS servers (primary or
secondary) are responsive, then when they reject a user, the unit will reject a user and
not
fall back to
authenticating with User Profiles. On the one hand this is an insurance policy against locking yourself out,
but on the other hand it still means you must maintain some local authentication/authorization security
configuration of the unit, which erodes the purpose of centralized AAA.
4. If you end up in a situation where you cannot log in to the unit at all, there is one last resort before
returning the unit. There is a way to gain access with the button unlock feature. If you tap the reset button
a few times (at least 5) until the front panel lights flash, then the unit defaults the following settings, which
enables you to log in to the unit via the console port using the default MASTER user profile:
o
sec.mode
(to USER PROFILES)
o
sec.consolereq
(to OFF)
o
sec.connectvia
(to every method of connecting)
o
"admin/password/MASTER" credentials for the user profile appropriate to the product
o
IO2 mode set to COMMAND (if applicable to product)
Note:
o
The button unlock feature can only be used if
sec.button.unlock
=ON
(which it is by default). If you
do not want the unit to grant access via this feature, then turn it off. However, if you subsequently lock
yourself out then there is no way to gain access to the unit: you must return it.
o
If you lock yourself out and gain access again with the button unlock feature, remember to reconfigure
the settings that were defaulted by the button unlock feature to maintain your prior security
configuration!
o
"tap the reset button" means press the reset button on the unit (the only button for the current
products) until it clicks and then release it, at a frequency of about 1-2 taps per second. Do not hold in
the reset button otherwise that will reset the unit, just tap it like you click a mouse button.
RADIUS server configuration
Some configuration for the RADIUS server is vendor-dependent, such as how you configure client machines and
users. Likewise there is vendor-independent configuration that tells the RADIUS server what vendor-specific RADIUS
attributes should be included in Access-Accept frames. All authorization data is encapsulated by these vendor-specific
attributes in a file called the RADIUS dictionary. The Asentria RADIUS dictionary (named dictionary.asentria) is
included on the resource CD that ships with the unit, or can be requested from
. It is meant
to be input into your RADIUS server. The attributes are listed below. When you configure a user on the RADIUS
server, you must in some way specify values for these attributes -- this is how you tell the RADIUS server (and the
unit) explicitly what a user is authorized to do. The values for each attribute correspond exactly to the traditional
settings used on the unit for User Profiles authorization.
Summary of Contents for Teleboss 850
Page 6: ......