60
Authentication
Access Control via Radius Attribute NAS-Port-id
This feature provides an additional way to control the access to serial ports other than
the one based in usernames or groups. The authentication type must be Radius for this
feature to function. The Radius server administrator must configure the user (in the
radius server database) with one NAS-PORT-id attribute for each serial port that the user
is allowed to access.
In the example below the user alfred can access the serial ports ttyS11, ttyS13, and
ttyS17:
alfred Auth-Type = Local, Password = ‘alfred’
Service-Type = Framed-User,
Framed-Protocol = PPP,
NAS-Port-Id = 11,
NAS-Port-Id = 13,
NAS-Port-Id = 17
The pam_radius module will check whether the NAS-Port-Id matches one of those sent
by the radius server. If the radius server does not send the NAS-Port-Id attribute, no
check is performed.
No configuration is needed for the ACS. However, the authentication type must be
“radius”. Authentications like radiusDownLocal, radius/local, etc. will not validate the
NAS-port-Id if the user was locally authenticated.
NIS Client
NIS (Network Information System) provides simple and generic client-server database
access facilities that can be used to distribute information. This makes the network
appear as a single system, with the same accounts on all hosts. The objective of this
feature is to allow the administrator to manage ACS accounts on a NIS server.
The NIS client feature needs these following files/commands:
File/Command
Description
/etc/yp.conf
This file contains the configuration used by ypbind.
/etc/domainname.conf
This file contains the NIS domain name (set by the command
domainname).
Table 3.3: NIS client requirements
Содержание AlterPath ACS
Страница 16: ...xvi Table of Contents...
Страница 29: ...13 This page has been left intentionally blank...
Страница 30: ...14 Preface...
Страница 68: ...52 Device Access...
Страница 86: ...70 Authentication Step 5 Saving changes To save the configuration run the command saveconf...
Страница 96: ...80 Authentication Save the configuration to flash 2 cli config savetoflash...
Страница 114: ...98 Authentication...
Страница 204: ...188 Administration To exit the CLI mode and return to ACS s shell issue the command cli quit...
Страница 268: ...252 Power Management with AlterPath PM Integration...
Страница 304: ...288 PCMCIA Cards Integration...
Страница 338: ...322 Profile Configuration...
Страница 364: ...348 Additional Features and Applications...
Страница 376: ...360 Appendix A New User Background Information...
Страница 406: ...390 Appendix C Cabling and Hardware Information This page has been left intentionally blank...
Страница 418: ...402 List of Tables...
Страница 420: ...404 List of Figures...