inS_CnGE28FX4TX_rEv–
08/31/12 PAGE 76
INSTALLATION AND OPERATION MANUAL
CNGE28FX4TX
Tech SupporT: 1.888.678.9427
The table has one row for each Client and a number of columns, which are:
Label
Description
Client
The Client for which the configuration below applies.
Authentication
Method
Authentication Method can be set to one of the following values:
none: authentication is disabled and login is not possible.
local: use the local user database on the switch stack for
authentication.
radius: use a remote RADIUS server for authentication.
: use a remote server for authentication.
Fallback
Enable fallback to local authentication by checking this box. If none
of the configured authentication servers are alive, the local user
database is used for authentication.
This is only possible if the Authentication Method is set to something
else than ‘none or ‘local’.
Save
Select to save changes.
Reset
Select to undo any changes made locally and revert to previously
saved values.
Common Server Configuration
These setting are common for all of the Authentication Servers.
Label
Description
Timeout
The Timeout, which can be set to a number between 3 and 3600
seconds, is the maximum time to wait for a reply from a server. If the
server does not reply within this timeframe, we will consider it to be
dead and continue with the next enabled server (if any).
RADIUS servers are using the UDP protocol, which is unreliable by
design. In order to cope with lost frames, the timeout interval is
divided into 3 subintervals of equal length. If a reply is not received
within the subinterval, the request is transmitted again. This algorithm
causes the RADIUS server to be queried up to 3 times before it is
considered to be dead.
Dead Time
The Dead Time, which can be set to a number between 0 and 3600
seconds, is the period during which the switch will not send new
requests to a server that has failed to respond to a previous request.
This will stop the switch from continually trying to contact a server that
it has already determined as dead.
Setting the Dead Time to a value greater than 0 (zero) will enable this
feature, but only if more than one server has been configured.