Security
ExtremeWare XOS 11.3 Concepts Guide
328
Complete the following two steps to limit the maximum concurrent login sessions under the same user
account:
1
Configure Radius and Radius-Accounting on the switch.
The Radius and Radius-Accounting servers used for this feature must reside on the same physical
Radius server. Standard Radius and Radius-Accounting configuration is required as described earlier
in this chapter.
2
Modify the Funk SBR ‘vendor.ini’ file and user accounts.
To configure the Funk SBR server, the file ‘
vendor.ini
’ must be modified to change the Extreme
Networks configuration value of ‘
ignore-ports’
to yes as shown in the example below:
vendor-product = Extreme Networks
dictionary = Extreme
ignore-ports = yes
port-number-usage = per-port-type
help-id = 2000
After modifying the ‘vendor.ini’ file, the desired user accounts must be configured for the Max-
Concurrent connections. Using the SBR Administrator application, enable the check box for ‘Max-
Concurrent connections’ and fill in the desired number of maximum sessions.
RADIUS Server Configuration Example (Merit)
Many implementations of RADIUS server use the publicly available Merit
©
AAA server application. To
get a copy, search for the server on the website at:
www.merit.edu
Included below are excerpts from relevant portions of a sample Merit RADIUS server implementation.
The example shows excerpts from the client and user configuration files. The client configuration file
(
ClientCfg.txt
) defines the authorized source machine, source name, and access level. The user
configuration file (
users
) defines username, password, and service type information.
ClientCfg.txt
#Client Name
Key
[type]
[version]
[prefix]
#----------------
---------------
--------------
---------
--------
#10.1.2.3:256
test
type = nas
v2
pfx
#pm1
%^$%#*(&!(*&)+
type=nas
pm1.
#pm2
:-):-(;^):-}!
type nas
pm2.
#merit.edu/homeless hmoemreilte.ses
#homeless
testing
type proxy
v1
#xyz.merit.edu
moretesting
type=Ascend:NAS v1
#anyoldthing:1234
whoknows?
type=NAS+ACCT_RFC
10.202.1.3
andrew-linux
type=nas
10.203.1.41
eric
type=nas
10.203.1.42
eric
type=nas
10.0.52.14
samf
type=nas
users
user
Password = ""
Filter-Id = "unlim"
admin
Password = "", Service-Type = Administrative
Filter-Id = "unlim"
eric Password = "", Service-Type = Administrative
Summary of Contents for ExtremeWare XOS 11.3
Page 20: ...Contents ExtremeWare XOS 11 3 Concepts Guide 20...
Page 25: ...1 Using ExtremeWare XOS...
Page 26: ......
Page 38: ...ExtremeWare XOS Overview ExtremeWare XOS 11 3 Concepts Guide 38...
Page 58: ...Accessing the Switch ExtremeWare XOS 11 3 Concepts Guide 58...
Page 146: ...Configuring Slots and Ports on a Switch ExtremeWare XOS 11 3 Concepts Guide 146...
Page 218: ...Status Monitoring and Statistics ExtremeWare XOS 11 3 Concepts Guide 218...
Page 240: ...Virtual LANs ExtremeWare XOS 11 3 Concepts Guide 240...
Page 248: ...Virtual Routers ExtremeWare XOS 11 3 Concepts Guide 248...
Page 278: ...Access Lists ACLs ExtremeWare XOS 11 3 Concepts Guide 278...
Page 288: ...Routing Policies ExtremeWare XOS 11 3 Concepts Guide 288 entry deny_rest if then deny...
Page 344: ...Security ExtremeWare XOS 11 3 Concepts Guide 344...
Page 393: ...2 Using Switching and Routing Protocols...
Page 394: ......
Page 454: ...Spanning Tree Protocol ExtremeWare XOS 11 3 Concepts Guide 454...
Page 484: ...Extreme Standby Router Protocol ExtremeWare XOS 11 3 Concepts Guide 484...
Page 514: ...IPv4 Unicast Routing ExtremeWare XOS 11 3 Concepts Guide 514...
Page 530: ...IPv6 Unicast Routing ExtremeWare XOS 11 3 Concepts Guide 530...
Page 538: ...RIP ExtremeWare XOS 11 3 Concepts Guide 538...
Page 556: ...OSPF ExtremeWare XOS 11 3 Concepts Guide 556...
Page 566: ...OSPFv3 ExtremeWare XOS 11 3 Concepts Guide 566...
Page 589: ...3 Appendixes...
Page 590: ......
Page 640: ...CNA Agent ExtremeWare XOS 11 3 Concepts Guide 640...
Page 670: ...Glossary ExtremeWare XOS 11 3 Concepts Guide 670...
Page 698: ...Index ExtremeWare XOS 11 3 Concepts Guide 698...