Bridge GUI Guide: Security Configuration
143
NOTE:
When using
an external authen-
tication server, user and
(when applicable) device
authentication settings
are configured in the ex-
ternal application.
4.3.3
Local User and Device Authentication
You can configure user and device authentication settings even
when the Bridge’s local authentication is disabled (the default).
The settings will only be applied when the local RADIUS server
is enabled (refer to Section 4.3.2).
4.3.3.1
Local User Authentication Accounts
Locally authenticating users are displayed on the
User Entries
list on
Configure
->
RADIUS Settings
->
Local Server
.
You cannot disable local user authentication, per se, except by
disabling local authentication entirely. There is, however, no
requirement that you configure local users.
The users for whom you create accounts can fall into one of
two categories:
Secure Client users - are running the Fortress Secure
Client on their connecting devices. They use the Bridge’s
local user authentication service to log on to the Bridge-
secured network. Secure Client users pass only encrypted
traffic on the Bridge’s encrypted interfaces.
Administrative users - use the Bridge’s local user
authentication service to log on to the management
interface of another Fortress Bridge on the network (or of
the local Bridge), when the administrative
Authentication
Method
on that Bridge is set to
RADIUS
. Administrative
users pass only encrypted traffic on the Bridge’s encrypted
interfaces.
When an administrative user logs on to the Bridge through
a local or remote Fortress
user
authentication database (as
configured on the relevant
Local Server
screen), a
Learned
administrative account is created for that user in the
administrator
authentication database. You can optionally
convert a
Learned
account to a local administrative account
that can be used if the original user authentication service
becomes unavailable (refer to Section 2.2.2.8).
One can optionally convert the learned account(s) to local
account(s) that can be used when external admin auth is
disabled.
Default User Authentication Settings
While idle timeout and session timeout settings can be
individually configured for each user, the default values for
these settings are determined by the
Default Idle Timeout
and
Default Session Timeout
values configured on the local RADIUS
server (refer to Section 4.3.2).