257
Limiting user access
Authenticating with an external authentication server
Remote Authentication Dial-In User Service (RADIUS) authentication
RADIUS is a UDP-based authentication method that the security gateway supports for FTP, Telnet,
NNTP, and HTTP connections.
Note:
For static RADIUS user authentication, you must have user accounts already defined on the
security gateway. For dynamic user authentication, users do not need to have local accounts.
Prerequisites
None.
To create a new RADIUS authentication server record
1
In the SGMI, in the left pane, under Assets, click
Authentication Servers
.
2
In the right pane, on the Authentication Servers tab, click
New > RADIUS
.
3
In the RADIUS Properties dialog box, on the General tab, do the following:
4
Optionally, on the Description tab, type a more detailed description than you typed in the Caption
text box.
5
Click
OK
.
6
Optionally, do the following:
■
To save your configuration now and activate later, on the toolbar, click
Save
.
■
To activate your configuration now, on the tool bar, click
Activate
.
When prompted to save your changes, click
Yes
.
7
After defining the RADIUS authentication server, you can use it in the following ways:
■
Identify the server to be used for authentication in an authentication scheme.
■
Use the server as the authentication server in a clientless VPN role.
Related information
For further information related to this topic, see the following:
■
“RADIUS Properties—General tab”
■
“RADIUS Properties—Description tab”
■
“Configuring an authentication scheme”
■
“Creating and assigning roles”
Name
Type a name for this authentication server.
Primary server
Type the IP address or fully-qualified domain name of the RADIUS server.
Primary server port
Type the UDP port number assigned to the RADIUS server.
Primary server secret
Type the primary RADIUS server shared secret key.
Alternate server
Type the IP address or fully-qualified domain name of the secondary RADIUS
server.
Alternate server port
Type the UDP port number assigned to the alternate RADIUS server.
Alternate server secret
Type the alternate RADIUS server shared secret key.
Caption
Type a brief description of the RADIUS server.
Summary of Contents for Security 5600 Series, Security 5400 Series,Clientless VPN 4400 Series
Page 76: ...76 Managing administrative access Enabling SSH for command line access to the appliance...
Page 242: ...242 Defining your security environment Controlling full application inspection of traffic...
Page 243: ...243 Defining your security environment Controlling full application inspection of traffic...
Page 269: ...268 Limiting user access Authenticating using Out Of Band Authentication OOBA...
Page 373: ...372 Preventing attacks Enabling protection for logical network interfaces...
Page 509: ...508 Generating reports Upgrade reports...
Page 553: ...552 Advanced system settings Configuring advanced options...
Page 557: ...556 SSL server certificate management Installing a signed certificate...
Page 861: ...860 Index...