•
For remotely authenticated administrators, a RADIUS authentication server handles
authentication. Because the administrator password is stored on the RADIUS server,
you do not need to enter the password again, however, the administrator must enter
the password at the NSM UI login screen.
To configure the RADIUS authentication server for NSM administrators, see the
Network
and Security Manager Online Help
topic “Editing the Domain Contact.”
NOTE:
The super administrator has full permissions. You cannot change or delete
permissions for the super administrator; you can only change the password. Because
the super administrator has complete control over NSM functionality, we recommend
that you consider the security of the super administrator password appropriately. If you
forget or lose the super administrator password, please contact the Juniper Technical
Assistance Center (JTAC).
RADIUS Authentication and Authorization
NSM supports both local and RADIUS user authentication. It manages access control
both through the local database and through the RADIUS server.
You are not required to define RADIUS users in the local NSM database. The AUTH
Handler looks at the local database to find the user, and then, if no match is found, to
the RADIUS server. You can also define the role assignment for each user directly from
the RADIUS server.
NOTE:
You must configure your RADIUS server individually for each domain.
NSM also supports a secondary RADIUS server for administrator authentication and
authorization when the primary RADIUS server cannot be contacted.
There are two kinds of users: local users and RADIUS users. The local user is created
locally and authentication data is stored in the local database. The default authentication
mode is local mode. The RADIUS user is created only on a RADIUS server and can only
be authenticated using a remote RADIUS server.
There are also two kinds of authentication modes for NSM users: local mode and RADIUS
mode. Both User and Domain can define these modes and Domain’s authentication
mode is applied to all the users within it. User’s Authentication mode has a higher priority
and can override Domain’s mode.
The NSM user is authenticated based on the rules listed in Table 15 on page 68.
Table 15: How to Authenticate Users
Authorization
Authentication Results
Domain
Auth
Mode
User
Auth
Mode
User in
Local
Database
Rule
Local
Authenticates user locally.
Local
Local
Defined
1
Copyright © 2010, Juniper Networks, Inc.
68
Network and Security Manager Administration Guide
Содержание NETWORK AND SECURITY MANAGER 2010.3
Страница 6: ...Copyright 2010 Juniper Networks Inc vi...
Страница 36: ...Copyright 2010 Juniper Networks Inc xxxvi Network and Security Manager Administration Guide...
Страница 52: ...Copyright 2010 Juniper Networks Inc 2 Network and Security Manager Administration Guide...
Страница 90: ...Copyright 2010 Juniper Networks Inc 40 Network and Security Manager Administration Guide...
Страница 144: ...Copyright 2010 Juniper Networks Inc 94 Network and Security Manager Administration Guide...
Страница 146: ...Copyright 2010 Juniper Networks Inc 96 Network and Security Manager Administration Guide...
Страница 234: ...Copyright 2010 Juniper Networks Inc 184 Network and Security Manager Administration Guide...
Страница 310: ...Copyright 2010 Juniper Networks Inc 260 Network and Security Manager Administration Guide...
Страница 364: ...Copyright 2010 Juniper Networks Inc 314 Network and Security Manager Administration Guide...
Страница 366: ...Copyright 2010 Juniper Networks Inc 316 Network and Security Manager Administration Guide...
Страница 478: ...Copyright 2010 Juniper Networks Inc 428 Network and Security Manager Administration Guide...
Страница 576: ...Copyright 2010 Juniper Networks Inc 526 Network and Security Manager Administration Guide...
Страница 580: ...Copyright 2010 Juniper Networks Inc 530 Network and Security Manager Administration Guide...
Страница 592: ...Copyright 2010 Juniper Networks Inc 542 Network and Security Manager Administration Guide...
Страница 684: ...Copyright 2010 Juniper Networks Inc 634 Network and Security Manager Administration Guide...
Страница 690: ...Copyright 2010 Juniper Networks Inc 640 Network and Security Manager Administration Guide...
Страница 696: ...Copyright 2010 Juniper Networks Inc 646 Network and Security Manager Administration Guide...
Страница 698: ...Copyright 2010 Juniper Networks Inc 648 Network and Security Manager Administration Guide...
Страница 748: ...Copyright 2010 Juniper Networks Inc 698 Network and Security Manager Administration Guide...
Страница 778: ...Copyright 2010 Juniper Networks Inc 728 Network and Security Manager Administration Guide...
Страница 870: ...Copyright 2010 Juniper Networks Inc 820 Network and Security Manager Administration Guide...
Страница 872: ...Copyright 2010 Juniper Networks Inc 822 Network and Security Manager Administration Guide...
Страница 898: ...Copyright 2010 Juniper Networks Inc 848 Network and Security Manager Administration Guide...
Страница 908: ...Copyright 2010 Juniper Networks Inc 858 Network and Security Manager Administration Guide...
Страница 910: ...Copyright 2010 Juniper Networks Inc 860 Network and Security Manager Administration Guide...
Страница 995: ...PART 6 Index Index on page 947 945 Copyright 2010 Juniper Networks Inc...
Страница 996: ...Copyright 2010 Juniper Networks Inc 946 Network and Security Manager Administration Guide...