
4-20
User Guide for the Avaya P580 and P882 Multiservice Switches, v6.0
Chapter 4
Realms
A Realm provides a mechanism by which a RADIUS manager can organize
user accounts. Consult the RADIUS vendor’s documentation on how to
create Realms on the server. Once created, user accounts are placed in the
realms. The realm name is also configured on the NADs and when the
NADs send Access Request messages, the user name is appended with an
“@” and the Realm name.
For example: User Bob in the AvayaRealm would log into the switch with
Bob. The Avaya switch would send the Access Request message with user
Bob@AvayaRealm. The RADIUS server, upon receiving the request, would
look for Bob in the AvayaRealm.
Groups and VSA
In order to provide user accounts with the same granularity of privileges as
on the Avaya switch, Vendor Specific Attributes (VSA) must be configured
on the RADIUS server and a Group name must be set on the Avaya switch.
When set, the Group name is sent along with the Access Request message
to the RADIUS server.
The RADIUS server will send an Access Accept message if the user name,
password, and Group name match that of the user account. If so, the Access
Accept message will include the VSAs that identify the privileges the user
has.
* Note: If a user has a Standard RADIUS account, one that does not
contain the Group name, the RADIUS server will still respond
with an Access Accept message; but the message will not
contain the Group name or the VSAs. This is a security
loophole. See the Switch-Service-Type-Required parameter
below for more information
Avaya Service-Types specify the level of privileges a user has. The
following three types are supported:
■
Administrative (can create user accounts and configure the Avaya
switch)
■
Read-Write (can configure the Avaya switch)
■
Read-Only (can view the Avaya switch configuration)
Avaya Management Types specify what method the user can use to manage
the switch. The following four types are supported:
■
Avaya Management All
■
Avaya Local CLI (Serial port on the supervisor)
■
Avaya Remote CLI (Telnet session)
■
Avaya Web Agent
Summary of Contents for Cajun P580
Page 26: ...xxvi User Guide for the Avaya P580 and P882 Multiservice Switches v6 0 Preface...
Page 50: ...1 24 User Guide for the Avaya P580 and P882 Multiservice Switches v6 0 Chapter 1...
Page 158: ...5 24 User Guide for the Avaya P580 and P882 Multiservice Switches v6 0 Chapter 5...
Page 308: ...10 18 User Guide for the Avaya P580 and P882 Multiservice Switches v6 0 Chapter 10...
Page 508: ...16 26 User Guide for the Avaya P580 and P882 Multiservice Switches v6 0 Chapter 16...
Page 530: ...18 14 User Guide for the Avaya P580 and P882 Multiservice Switches v6 0 Chapter 18...
Page 622: ...21 22 User Guide for the Avaya P580 and P882 Multiservice Switches v6 0 Chapter 21...
Page 652: ...23 20 User Guide for the Avaya P580 and P882 Multiservice Switches v6 0 Chapter 23...
Page 660: ...24 8 User Guide for the Avaya P580 and P882 Multiservice Switches v6 0 Chapter 24...
Page 714: ...25 54 User Guide for the Avaya P580 and P882 Multiservice Switches v6 0 Chapter 25...
Page 728: ...Appendix B B 4 User Guide for the Avaya P580 and P882 Multiservice Switches v6 0...