
Adding Users through RADIUS
The RADIUS system administrator can add VPN Gateway administrator users to the RADIUS
configuration without being an administrator of the AVG, because the users do not need to be
configured locally on the AVG. By assigning suitable administrator groups to these users in
RADIUS, the users can be given the desired access rights to the CLI/BBI.
When the user logs in to the CLI/BBI and is successfully authenticated, the RADIUS server
returns the groups to which the user belongs. The groups are compared to the fixed
administrator groups on the VPN Gateway, that is, tunnelguard, admin, oper and certadmin.
If a match is found, the logged on user is given the administration rights pertaining to matching
group(s). Otherwise, the user is denied access.
See the
/cfg/sys/adm/auth/group
command in the
Avaya VPN Gateway User Guide
.
Changing a Users Group Assignment
Only users who are members of the admin group can remove other users from a group. All
users can add an existing user to a group, but only to a group in which the "granting" user is
already a member. The admin user, who by default is a member of all four groups (admin,
oper, tunnelguard and certadmin) can therefore add users to any of these groups.
1. Log in to the AVG cluster.
In this example the cert_admin user, who is a member of the certadmin group, will
add the admin user to the certadmin group. The example assumes that the admin
user previously removed himself or herself from the certadmin group, to fully
separate the Administrator user role from the Certificate Administrator user role.
login:
cert_admin
Password:( cert_admin user password)
2. Access the User Menu.
>> Main#
/cfg/sys/user
[User Menu]
-----------------------------------------------------
-------
passwd
- Change own password
expire
- Set password expire time
interval
Managing Users and Groups
80 User Guide
April 2013
Comments? [email protected]
Содержание 3050-VM
Страница 1: ...User Guide Avaya VPN Gateway Release 9 0 NN46120 104 Issue 04 04 April 2013 ...
Страница 4: ...4 User Guide April 2013 Comments infodev avaya com ...
Страница 12: ...12 User Guide April 2013 ...
Страница 20: ...New in this release 20 User Guide April 2013 Comments infodev avaya com ...
Страница 30: ...Introducing the VPN Gateway 30 User Guide April 2013 Comments infodev avaya com ...
Страница 36: ...Introducing the ASA 310 FIPS 36 User Guide April 2013 Comments infodev avaya com ...
Страница 74: ...Upgrading the AVG Software 74 User Guide April 2013 Comments infodev avaya com ...
Страница 86: ...Managing Users and Groups 86 User Guide April 2013 Comments infodev avaya com ...
Страница 130: ...The Command Line Interface 130 User Guide April 2013 Comments infodev avaya com ...
Страница 162: ...Supported Ciphers 162 User Guide April 2013 Comments infodev avaya com ...
Страница 212: ...Syslog Messages 212 User Guide April 2013 Comments infodev avaya com ...
Страница 242: ...Definition of Key Codes 242 User Guide April 2013 Comments infodev avaya com ...
Страница 259: ...Creating a Port Forwarder Authenticator User Guide April 2013 259 ...
Страница 265: ...This will print current statistics every 3 seconds Monitoring the Port Forwarder User Guide April 2013 265 ...
Страница 266: ...Using the Port Forwarder API 266 User Guide April 2013 Comments infodev avaya com ...
Страница 274: ...X 509 274 User Guide April 2013 Comments infodev avaya com ...