Securit y planning
Chapt er 2: Planning considerat ions
2- 28
phn- 2513_004v000 ( Oct 2012)
Planning for RADIUS operation
Configure RADIUS where remote authentication is required for users of the web-based
interface. Remote authentication has the following advantages:
•
Control of passwords can be centralized.
•
Management of user accounts can be more sophisticated For example, users can be
prompted by email to change passwords at regular intervals. As another example,
passwords can be checked for inclusion of dictionary words and phrases.
•
Passwords can be updated without reconfiguring multiple network elements.
•
User accounts can be disabled without reconfiguring multiple network elements.
Remote authentication has one significant disadvantage in a wireless link product such as
PTP 800. If the wireless link is down, a unit on the remote side of the broken link may be
prevented from contacting a RADIUS Server, with the result that users are unable to
access the web-based interface.
One useful strategy would be to combine RADIUS authentication for normal operation with
a single locally-authenticated user account for emergency use.
PTP 800 provides a choice of three authentication methods:
•
CHAP
•
MS-CHAPv2
•
PEAP(MS-CHAPv2)
PEAP(MS-CHAPv2) is supported for Microsoft Windows Server 2003.
Ensure that the authentication method selected in PTP 800 is supported by the RADIUS
server.
RADIUS is not permitted in FIPS 140-2 applications. RADIUS and PEAP(MS-CHAPv2) are
mandatory in UC-APL applications.
RADIUS attributes
If the standard RADIUS attribute session-timeout (Type 27) is present in a RADIUS
response, PTP 800 sets a maximum session length for the authenticated user. If the
attribute is absent, the maximum session length is infinite.
If the standard RADIUS attribute idle-timeout (Type 28) is present in a RADIUS response,
PTP 800 overrides the Auto Logout Timer with this value in the authenticated session.
Содержание PTP 800 Series
Страница 1: ...Cambium PTP 800 Series User Guide System Release 800 05 02 ...
Страница 40: ...Licensing requirements About This User Guide 10 phn 2513_004v000 Oct 2012 ...
Страница 232: ...Limit of liability Chapter 3 Legal information 3 22 phn 2513_004v000 Oct 2012 ...
Страница 322: ...Radiation hazard assessm ent Chapter 4 Reference information 4 90 phn 2513_004v000 Oct 2012 ...
Страница 418: ...Replacing IRFU components Chapter 5 Installation 5 96 phn 2513_004v000 Oct 2012 Figure 1 1 0 IRFU components example ...
Страница 428: ...Replacing IRFU components Chapter 5 Installation 5 106 phn 2513_004v000 Oct 2012 ...
Страница 552: ...Configuring for FIPS 140 2 applications Chapter 6 Configuration and alignment 6 124 phn 2513_004v000 Oct 2012 ...
Страница 630: ...Using recovery mode Chapter 7 Operation 7 78 phn 2513_004v000 Oct 2012 ...
Страница 648: ...Glossary I V phn 2513_004v000 Oct 2012 ...