Chapter 6: User Management
115
Returning User Group Information via RADIUS
When a RADIUS authentication attempt succeeds, the Dominion KX II
determines the permissions for a given user based on the permissions of
the user's group.
Your remote RADIUS server can provide these user group names by
returning an attribute, implemented as a RADIUS FILTER-ID. The
FILTER-ID should be formatted as follows: Raritan:G{
GROUP_NAME
}
where
GROUP_NAME
is a string denoting the name of the group to
which the user belongs.
Raritan:G{GROUP_NAME}:D{Dial Back Number}
where GROUP_NAME is a string denoting the name of the group to
which the user belongs and Dial Back Number is the number associated
with the user account that the Dominion KX II modem will use to dial
back to the user account.
RADIUS Communication Exchange Specifications
The Dominion KX II sends the following RADIUS attributes to your
RADIUS server:
Attribute
Data
Log in
Access-Request (1)
NAS-Port-Type (61)
VIRTUAL (5) for network connections.
NAS-IP-Address (4)
The IP address for the Dominion KX II.
User-Name (1)
The user name entered at the login screen.
Acct-Session-ID (44)
Session ID for accounting.
User-Password(2)
The encrypted password.
Accounting-Request(4)
Acct-Status (40)
Start(1) - Starts the accounting.
NAS-Port-Type (61)
VIRTUAL (5) for network connections.
NAS-Port (5)
Always 0.
NAS-IP-Address (4)
The IP address for the Dominion KX II.
User-Name (1)
The user name entered at the login screen.
Acct-Session-ID (44)
Session ID for accounting.
Summary of Contents for Dominion KX2-864
Page 13: ...Chapter 1 Introduction 4...
Page 15: ...Chapter 1 Introduction 6 Product Photos Dominion KX II KX2 832...
Page 16: ...Chapter 1 Introduction 7 KX2 864...
Page 87: ...Chapter 4 Virtual Media 78...
Page 109: ...Chapter 6 User Management 100...
Page 141: ...Chapter 7 Device Management 132 3 Click OK...