Technical basics
3.8 Security functions
SCALANCE SC-600 Web Based Management (WBM)
Configuration Manual, 10/2021, C79000-G8976-C475-03
53
If you have set the authorization mode "SiemensVSA", the authentication of users via a
RADIUS server runs as follows:
1.
The user logs on with user name and password on the device.
2.
The device sends an authentication request with the login data to the RADIUS server.
3.
The RADIUS server runs a check and signals the result back to the device.
Case A
: The RADIUS server reports a successful authentication and returns the group
assigned to the user to the device.
–
The group is known on the device and the user is not entered in the table "External
User Accounts"
→ The user is logged in w
ith the rights of the assigned group.
–
The group is known on the device and the user is entered in the table "External
User Accounts"
→ The user is assigned the role with the higher rights and logged in with these
rights.
–
The group is not known on the device and the user is entered in the table "External
User Accounts"
→ The user is logged in with the rights of the role linked to the user account.
–
The group is not known on the device and the user is not entered in the table
"External User Accounts"
→ The use
r is logged in with the rights of the role "Default".
Case B:
The RADIUS server reports a successful authentication but does not return a
group to the device.
–
The user is entered in the table "External User Accounts":
→ The user is logged in with the right
s of the linked role "".
–
The user is not entered in the table "External User Accounts":
→ The user is logged in with the rights of the role "Default".
Case C:
The RADIUS server reports a failed authentication to the device:
–
The user is denied access.
Summary of Contents for SIMATIC NET SCALANCE SC-600
Page 68: ......