............................................................................................................................................................................................................................................................
RADIUS Terms Explained
Introduction to 8950 AAA
1-4
365-360-001 R6.0
Issue 1, December 2008
............................................................................................................................................................................................................................................................
8950 AAA requires that at least one policy be defined, but it can be configured to handle
many policies. You decide how many policies are necessary based on your business needs.
The needs can range from the type and level of services you provide, equipment
requirements, and customer requirements, to the geographic location of your customers
and the time of day.
This document will describe use of the 8950 AAA PolicyAssistant to define access
policies. It is also possible to create custom access policies using the 8950 AAA
PolicyFlow programming language. Please refer to the 8950 AAA Programmer’s
Reference Manual.
Authentication and Authorization Activities
As mentioned previously, a user source is a data repository that contains user information
called user profiles. 8950 AAA can access information stored in a variety of user sources.
A user source might be one of the following:
•
Standard text files, such as a RADIUS User file commonly used in publicly available
RADIUS servers
•
SQL databases, such as Oracle, Sybase, MySQL, or the built-in database
•
An LDAP (Lightweight Directory Access Protocol) server or a server that supports
LDAP queries, for example, Microsoft Active Directory or Novell NetWare directory
A user profile typically contains the user’s name and password. Some user profiles may
also contain information that describes the connection type, allowed services,
authentication means, and session limits specific to a user.
The term authentication source refers to the place where the user’s authentication
information, typically a password, is stored, for example, the user’s profile, or an external
service that authenticates the user. An example of an external service is a secure token
server.
Table 1-1
provides a list of supported sources for user profiles and a description of each. It
is possible to read a user profile from one source and use a different source for
authentication. For example, the user profile might be stored in LDAP while an RSA ACE
(SecurID) might be used for authentication.
Table 1-1 Supported Sources for User Profiles
User Source
Description
RADIUS User File
A text file that conforms to a traditional format as
used in many freeware RADIUS servers
Содержание 8950 AAA
Страница 8: ...Contents v i i i 365 360 001R6 0 Issue 1 December 2008...
Страница 18: ...1 2 365 360 001R6 0 Issue 1 December 2008...
Страница 24: ...RADIUS Terms Explained Introduction to 8950 AAA 1 6 365 360 001 R6 0 Issue 1 December 2008...
Страница 140: ...Method Dispatch Section Using the 8950 AAA Policy Flow Editor 8 12 365 360 001R6 0 Issue 1 December 2008...
Страница 186: ...USSv2 Configuration Configuring 8950 AAA USSv2 10 8 365 360 001R6 0 Issue 1 December 2008...
Страница 204: ...Modifying a System Operator Configuring 8950 AAA Operators 11 18 365 360 001R6 0 Issue 1 December 2008...
Страница 210: ...Simple Address Manager Configuration Configuring Simple Address Manager 12 6 365 360 001R6 0 Issue 1 December 2008...
Страница 218: ...II 2 365 360 001R6 0 Issue 1 December 2008...
Страница 224: ...Stats Collector Panel Stats Collector 14 6 365 360 001R6 0 Issue 1 December 2008...
Страница 230: ...The Configure Reports Panel Configuring Reports 15 6 365 360 001R6 0 Issue 1 December 2008...
Страница 232: ...III 2 365 360 001R6 0 Issue 1 December 2008...
Страница 276: ...Log Rules Message Logging 16 44 365 360 001R6 0 Issue 1 December 2008...
Страница 278: ...IV 2 365 360 001R6 0 Issue 1 December 2008...
Страница 326: ...Advanced Using LiveAdministrator 18 16 365 360 001R6 0 Issue 1 December 2008...
Страница 328: ...V 2 365 360 001R6 0 Issue 1 December 2008...
Страница 356: ...Diameter Applications Tab 8950 AAA Dictionary Editor 20 12 365 360 001R6 0 Issue 1 December 2008...
Страница 400: ...VI 2 365 360 001R6 0 Issue 1 December 2008...
Страница 426: ...VII 2 365 360 001R6 0 Issue 1 December 2008...
Страница 458: ...List of Server Commands Server Diagnostics and Control Commands 24 32 365 360 001R6 0 Issue 1 December 2008...
Страница 460: ...VIII 2 365 360 001R6 0 Issue 1 December 2008...
Страница 474: ...Glossary GL 10 365 360 001R6 0 Issue 1 December 2008...