Bridge GUI Guide: Administrative Access
22
log-ons and
Monitor
->
Event Log
when
Log Viewer
accounts
first access the Bridge GUI). The feature is
Disabled
by default.
Show Previous Logon
is present only in Advanced View (refer to
2.2.1.6
Authentication Method and Failback
NOTE:
Adminis-
trators added in
the external authentica-
tion service are
Learned
by the Bridge, but can-
not be authenticated un-
til their records have
been opened locally for
configuration (refer to
Section 2.2.2.8).
By default, administrative
Usernames
and passwords are
authenticated by the
Local
administrator
authentication
service—a designated service running on the Bridge itself and
separate from the local
user
authentication service configured
on
Configure
->
RADIUS Settings
->
Local Server
(refer to
Alternatively, you can reconfigure the Bridge to send
administrators’ logon credentials to a Remote Authentication
Dial-In User Service (
RADIUS
) server, which may be any of:
the RADIUS server internal to the current Bridge
the RADIUS server internal to another Bridge on the
network
a third-party RADIUS server running on the network
The service(s) available are determined by the Bridge’s
configuration for authentication servers as determined by the
settings on
Configure
->
RADIUS Settings
.
When a Fortress or a third-party
RADIUS
server is used to
evaluate administrator logon credentials, locally configured
logon settings and password rules do not apply. Administrative
logon behavior and password rules are determined by the
account settings in effect on that
RADIUS
server.
When the Bridge is configured to use a third-party or Fortress
RADIUS
server and
Authentication Failback
is
Enabled
, the
Bridge will use its local administrator authentication service as
a backup means of authenticating administrator credentials,
should the third-party or Fortress user authentication database
become unavailable.
When
Authentication Failback
is disabled (the default) on a
Bridge configured to use a third-party or Fortress
RADIUS
server for administrator authentication, and no such server is
available, administrators cannot be authenticated and logged
on to the Bridge until access to the external server is restored.
Authentication Failback
is not applicable to Bridges configured
with the default
Authentication Method
of
Local
.
Authentication Method
and
Authentication Failback
are present
only in Advanced View (refer to Section 2.1.4).
To use the local Fortress RADIUS Server
to authenticate administrators:
Except for steps 7 through 11, which can be performed at any
time, you
must
follow the steps of the procedure below in the
order given.