Industrial Managed
Ethernet Switch – EH9711
User Manual
Page
83
of
223
Authorization
—Provides access control. AAA authorization is the process of assembling a set of attributes that describe
what the user is authorized to perform. Authorization in EH9711 switches is provided by attributes that are downloaded
from AAA servers. Remote security servers, such as RADIUS and , authorize users for specific rights by
associating attribute-value (AV) pairs, which define those rights with the appropriate user.
Accounting
—Provides the method for collecting information, logging the information locally, and sending the
information to the AAA server for billing, auditing, and reporting. The accounting feature tracks and maintains a log of
every management session used to access EH9711 switches. You can use this information to generate reports for
troubleshooting and auditing purposes. You can store accounting logs locally or send them to remote AAA servers.
AAA increases flexibility and control of access configuration, scalability, standardized authentication methods, such as
RADIUS and , and multiple backup devices.
2.5.3.1
RADIUS
RADIUS (Remote Authentication Dial in User Service)
is an access server that uses authentication, authorization, and
accounting (AAA) protocol for authentication and authorization. It is a distributed security system that secures remote access
to networks and network services against unauthorized access. The RADIUS specification is described in RFC 2865, which
obsoletes RFC 2138. Figure 2.67 shows the
RADIUS Server Configuration
webpage which allows the users to configure up
to 5 RADIUS servers. It is divided into two parts:
Global Configuration
and
Server Configuration
. Table 2.54 summarizes
the parameters for the
RADIUS Server Configuration
.
Figure 2.67 Webpage
to Configure AAA RADIUS
Table 2.54 Descriptions of AAA RADIUS
Label
Description
Factory
Default
Global Configuration
Timeout
Timeout is the number of seconds, in the range 1 to 1000, to wait for a reply from
a RADIUS server before retransmitting the request.
5
Retransmit
Retransmit is the number of times, in the range 1 to 1000, a RADIUS request is
retransmitted to a server that is not responding. If the server has not responded
after the last retransmit it is considered to be dead.
3
Deadtime
Deadtime, which can be set to a number between 0 to 1440 minutes, is the period
during which the switch will not send new requests to a server that has failed to
respond to a previous request. This will stop the switch from continually trying to
contact a server that it has already determined as dead.
Setting the Deadtime to a value greater than 0 (zero) will enable this feature, but
only if more than one server has been configured.
0