88
D
OMINION
KX
II
U
SER
G
UIDE
Returning User Group Information via RADIUS
When a RADIUS authentication attempt succeeds, the Dominion KX II device determines the
permissions for a given user based on the permissions of the user’s group.
Your remote RADIUS server can provide these user group names by returning an attribute,
implemented as a RADIUS
FILTER-ID
. The
FILTER-ID
should be formatted as follows:
Raritan:G{GROUP_NAME}
where
GROUP_NAME
is a string, denoting the name of the group to which the user belongs.
RADIUS Communication Exchange Specifications
The Dominion KX II unit sends the following RADIUS attributes to your RADIUS server:
A
TTRIBUTE
D
ATA
L
OGIN
Access-Request (1)
NAS-Port-Type (61)
VIRTUAL (5) for network connections.
NAS-IP-Address (4)
The IP Address for the Dominion KX II unit.
User-Name (1)
The user name entered at the login screen.
Acct-Session-ID (44)
Session ID for accounting.
User-Password(2):
The encrypted password.
Accounting-Request(4)
Acct-Status (40)
Start(1) – Starts the accounting.
NAS-Port-Type (61)
VIRTUAL (5) for network connections.
NAS-Port (5)
Always 0.
NAS-IP-Address (4)
The IP Address for the Dominion KX II unit.
User-Name (1)
The user name entered at the login screen.
Acct-Session-ID (44)
Session ID for accounting.
L
OGOUT
Accounting-Request(4)
Acct-Status (40)
Stop(2) – Stops the accounting
NAS-Port-Type (61)
VIRTUAL (5) for network connections.
NAS-Port (5)
Always 0.
NAS-IP-Address (4)
The IP Address for the Dominion KX II unit.
User-Name (1)
The user name entered at the login screen.
Acct-Session-ID (44)
Session ID for accounting.
Summary of Contents for Dominion KX II Server KX2-432
Page 2: ...This page intentionally left blank...
Page 12: ...viii FIGURES...
Page 40: ...28 DOMINION KX II USER GUIDE...
Page 76: ...64 DOMINION KX II USER GUIDE...
Page 187: ...APPENDIX D FAQS 175 255 62 4023 00...