
Configuration
Operating Manual PCOM sec br2
1004534-EN-04
| 25
8.3.2
User groups
User groups are created on the user interface so that each user is assigned the permis-
sions appropriate for their role.
You can create a maximum of 15 user groups with different permissions. Each user is as-
signed to a user group.
The following user group is pre-configured on delivery:
Name
: Administrators
Permissions
: Administration
Delegating allowed
: No
Allow delegating
Management of user data can normally only be undertaken by system users with
Adminis-
tration
permission.
For certain user groups, management of the user data can be delegated to system users
with
UserManagement
permission.
With user groups whose user data management is to be delegated, the
Allow delegating
option must be activated.
The following actions can then be delegated:
}
List users
}
Create new user
}
Change user data
8.3.3
Create user
A user account must be created for each user who wants to access the protected system
via VPN client or the SecurityBridge user interface.
To do this, create a new user in the user interface:
}
Specify user name and password
}
Assign rights by selecting the user group and setup mode
8.3.4
Manage user via RADIUS server
User management can also be run via a central RADIUS server, as an alternative to local
user management on the user interface of the SecurityBridge.
On the user interface, a primary and secondary RADIUS server can be configured. On the
user interface you define which user groups or permissions are to be used for the RADIUS
server.
}
A secure Server Shared Secret must be entered to configure the RADIUS server. The
same Server Shared Secret must be configured on the RADIUS server.
}
Use a separate Server Shared Secret for each SecurityBridge that is configured via the
RADIUS server.