Some important points should be noted about activation:
•
RADIUS Accounting will not function where a connection is subject to a FwdFast rule in the IP
rule set.
•
The same RADIUS server does not need to handle both authentication and accounting; one
server can be responsible for authentication while another is responsible for accounting tasks.
•
Multiple RADIUS servers can be configured in NetDefendOS to deal with the event when the
primary server is unreachable.
Example 2.13. RADIUS Accounting Server Setup
This example shows configuring of NetDefendOS with a local RADIUS server called my-accounting using IP
address 192.168.03.01 and port 1813. Assume the shared secret is 231562514098273.
Command-Line Interface
gw-world:/> add RadiusAccounting my-accounting
IPAddress=192.168.03.01
SharedSecret=231562514098273
Port=1813
RetryTimeout=2
RoutingTable=main
Web Interface
1.
Go to: User Authentication > Accounting Servers > Add > Radius Server
2.
Now enter:
•
Name: my-accounting
•
IP Address: 192.168.03.01
•
Port: 1813
•
Retry Timeout: 2
•
Shared Secret: 231562514098273
•
Confirm Secret: 231562514098273
•
Routing Table: main
3.
Click OK
2.3.5. RADIUS Accounting Security
Communication between NetDefendOS and any RADIUS accounting server is protected by the use
of a shared secret. This secret is never sent over the network but instead a 16 byte long
Authenticator code is calculated using a one way MD5 hash function and this is used to authenticate
accounting messages.
The shared secret is case sensitive, can contain up to 100 characters, and must be typed exactly the
same for NetDefendOS and for the RADIUS server.
Messages are sent using the UDP protocol and the default port number used is 1813 although this is
user configurable.
2.3.6. RADIUS Accounting and High Availability
2.3.5. RADIUS Accounting Security
Chapter 2. Management and Maintenance
69
Содержание NetDefend DFL-1660
Страница 28: ...1 3 NetDefendOS State Engine Packet Flow Chapter 1 NetDefendOS Overview 28 ...
Страница 88: ...2 6 3 Restore to Factory Defaults Chapter 2 Management and Maintenance 88 ...
Страница 166: ...3 10 DNS Chapter 3 Fundamentals 166 ...
Страница 254: ...4 7 5 Advanced Settings for Transparent Mode Chapter 4 Routing 254 ...
Страница 268: ...5 4 IP Pools Chapter 5 DHCP Services 268 ...
Страница 368: ...6 7 Blacklisting Hosts and Networks Chapter 6 Security Mechanisms 368 ...
Страница 390: ...7 4 7 SAT and FwdFast Rules Chapter 7 Address Translation 390 ...
Страница 414: ...8 3 Customizing Authentication HTML Pages Chapter 8 User Authentication 414 ...
Страница 490: ...9 8 6 Specific Symptoms Chapter 9 VPN 490 ...
Страница 528: ...10 4 6 Setting Up SLB_SAT Rules Chapter 10 Traffic Management 528 ...
Страница 544: ...11 7 HA Advanced Settings Chapter 11 High Availability 544 ...
Страница 551: ...12 3 5 Limitations Chapter 12 ZoneDefense 551 ...
Страница 574: ...Default 512 13 9 Miscellaneous Settings Chapter 13 Advanced Settings 574 ...
Страница 575: ...13 9 Miscellaneous Settings Chapter 13 Advanced Settings 575 ...