System Cards
7-7
CPU Card
CPU Card User Screens and Settings
"SERVER: the IP address of the RADIUS server
"FALLBACK: see explanation below
"PORT: UDP port that the RADIUS server uses to receive authentication packets from
its clients. The default is 1812.
"TIMEOUT: How many seconds the system will wait for a response from the RADIUS
server. The default is 3.
"RETRIES: The number of attempts that the IMACS will try to authenticate the
password if there is no response from the server. The default is 3.
"SECRET: This is the shared secret key between the IMACS and the RADIUS server.
The secret key is a case-sensitive text string up to 64 characters long. The secret key on
the server must match exactly the secret key on the IMACS. Along with alpha-numeric
characters, these special characters are also allowed: ~!@#$%^&*()_+|\=-'{}[]:"';<>?/.,
Fallback allows for access to the IMACS shelf from the console port should the RADIUS
server not respond for whatever reason. The IMACs will then process username and password
authentication locally, as if the RADIUS feature were not enabled. This is only true if
RADIUS is turned on, fallback is enabled and the RADIUS server cannot be reached.
WARNING!Saving the RADIUS setup without fallback will from that point on require the
RADIUS server to authenticate the user. Failure to have the server setup, or failure to be
able to reach the server will deny the user access to the node. Zhone Technologies or its
affiliates will not be able to grant access to the IMACS shelf.
For the server side, the following Vendor Specific Attributes (VSA) are required in order to
authenticate the IMACS Radius authentication request:
Vendor ID: 5504
Attribute: Zhone-IMACS-User-Group
The Zhone-IMACS-User-Group is an integer value ranging form 1-32 and this correlates to
the User Group Permissions as defined on the IMACS system.
When you define a user on the RADIUS server, you must also provide the
Zhone-IMACS-User-Group attribute associated with that user in order for the IMACS system
to pass the correct group privileges when the user logs into the system.
Following is an example from a FreeRADIUS server:
Summary of Contents for IMACS 8000
Page 20: ...xviii Table of Contents Model No Running Head Table of Contents...
Page 38: ...1 6 Reference Guide Model No Running Head Customer Service and Ordering Information What s New...
Page 82: ...4 18 Reference Guide Model No Running Head PWE IP Uplink Server 8000 PWE Applications...
Page 270: ...7 60 System Cards Model No Running Head CPU Card Specifications CPU Card...
Page 300: ...8 30 System Cards Model No Running Head Interface Card Specifications Interface Card...
Page 352: ...9 52 System Cards Model No Running Head WAN Card Specifications WAN Card...
Page 360: ...10 8 System Cards Model No Running Head Alarm Card Troubleshooting Alarm Cards...
Page 382: ...11 22 Voice Cards Model No Running Head E M Card Specifications E M Card...
Page 474: ...14 54 Data Cards Model No Running Head HSU Card Specifications HSU Card...
Page 484: ...15 10 Data Cards Model No Running Head OHSU Card Specification OHSU 4P Card...
Page 536: ...18 8 Data Cards Model No Running Head DS0 DP Card Specifications DS0 DP Card...
Page 596: ...21 38 Server Cards Model No Running Head IPR 4 Server Card Specifications IPR 4 Router Card...
Page 614: ...22 18 Server Cards Model No Running Head ACS MCC Card Troubleshooting MCC Card...
Page 644: ...24 18 Server Cards Model No Running Head PWE Card Troubleshooting PWE Card...
Page 674: ...A 30 Reference Guide Model No Running Head...
Page 729: ...Pin Outs C 31 C 8 HSU Cards...