Setting Up Authentication
53
Access Server Administrators’ Reference Guide
5 • Authentication
as freeware for most computer platforms and is an excellent method for managing user dial-in security.
Any RADIUS entries will require an associated server to process authentication requests from the access
server or the access server will reject users access. For more information about RADIUS, see RADIUS User
Authentication, below.
•
tacacs Users(3)—This feature is not currently available
•
static Then RADIUS(4)—Check the internal user database first, if no match is found, then use RADIUS
to authenticate and provision user services.
•
static Then Tacacs(5)— Check the internal user database first, if no match is found, then use TACACS to
authenticate and provision user services. Not currently implemented.
Note
The following options apply only when using an external authentica-
tion server.
Host Address (auHostAddress)
Tells the access server the IP address of the primary external authentication server. This must be the IP address
as the access server will not resolve a Fully Qualified Domain Name.
Secondary Host Address (auSecondaryHostAddress)
When using a remote authentication server (RADIUS) this variable provides an alternative server IP address.
Host Port (auHostPort)
This variable tells the access server which UDP port to use when connecting to the host specified in the Host
Address variable. The RADIUS standard, as per RFC 2138, specifies port 1812 for RADIUS authentication.
Some older installations of RADIUS use port 1645.
Timeout (auTimeout)
This option specifies the time, in seconds, before the access server will retransmit an authentication request to
an external authentication server.
Retries (auRetries)
This option specifies the number of times the access server will resend an authentication request to a RADIUS
server after a TIMEOUT occurs. If this number is exceeded then the secondary host will be tried. If this num-
ber is exceeded by the secondary host, the user will be rejected.
Secret (auSecret)
The Secret variable sets the shared secret between the authentication client (access server) and the authentica-
tion server (RADIUS). It is used to encrypt an authentication request and to decrypt an incoming reply from
the server. The secret on the access server and the RADIUS server must match and must be 15 or fewer print-
able, non space, ASCII characters.
Note
The same secret word must used on the access server and in the
RADIUS clients file.
Summary of Contents for Access Server
Page 24: ...Contents Access Server Administrators Reference Guide 24 ...
Page 28: ...About this guide Model 2960 RAS Getting Started Guide 28 ...
Page 58: ...5 Authentication Access Server Administrators Reference Guide 58 Static User Authentication ...
Page 94: ...7 Dial In Access Server Administrators Reference Guide 94 Dial In User Statistics window ...
Page 110: ...8 Dial Out Access Server Administrators Reference Guide 110 Dial Out User Statistics window ...
Page 134: ...12 Filter IP Access Server Administrators Reference Guide 134 Defining a filter ...
Page 174: ...17 MFR Version 2 Access Server Administrators Reference Guide 174 ...
Page 184: ...17 MFR Version 2 Access Server Administrators Reference Guide 184 MFR Version 2 Modify ...
Page 190: ...18 RIP Version 2 Access Server Administrators Reference Guide 190 RIP Version 2 Statistics ...
Page 196: ...19 SNMP Access Server Administrators Reference Guide 196 Out ...
Page 248: ...23 TCP Access Server Administrators Reference Guide 248 TCP Details ...
Page 252: ...24 UDP Access Server Administrators Reference Guide 252 Introduction ...
Page 258: ...26 License Access Server Administrators Reference Guide 258 End User License Agreement ...