![Black Box LS1016A User Manual Download Page 101](http://html.mh-extra.com/html/black-box/ls1016a/ls1016a_user-manual_2763435101.webp)
Chapter 3 - Additional Features
User Guide
101
all.authtype
(cont.)
•
kerberos
(authentication is performed using a kerberos server. The
IP address and other details of the kerberos server are defined in the
file /etc/krb5.conf)
•
local/radius
(authentication is performed locally first, switching to
Radius if unsuccessful)
•
radius/local
(the opposite of the previous option)
•
local/TacacsPlus
(authentication is performed locally first, switch-
ing to TacacsPlus if unsuccessful)
•
TacacsPlus/local
(the opposite of the previous option)
•
RadiusDownLocal
(local authentication is tried only when the
Radius server is down)
•
TacacsPlusDownLocal
(local authentication is tried only when the
TacacsPlus server is down)
Note that this parameter controls the authentication required by the
BLACK BOX
®
Advanced Console Server. The authentication required
by the device to which the user is connecting is controlled separately.
all.authhost1
all.authhost2
This address indicates the location of the Radius/TacacsPlus
authentication server and is only necessary if this option is chosen in
the previous parameter. A second Radius/TacacsPlus authentication
server can be configured with the parameter all.authhost2.
all.accthost1
all.accthost2
This address indicates the location of the Radius/TacacsPlus accounting
server, which can be used to track how long users are connected after
being authorized by the authentication server. Its use is optional. If this
parameter is not used, accounting will not be performed. If the same
server is used for authentication and accounting, both parameters must
be filled with the same address. A second Radius/TacacsPlus accounting
server can be configured with the parameter all.accthost2.
all.radtimeout
This is the timeout (in seconds) for a Radius authentication query to be
answered.