(e-mail address); during phase 2, the device prompts the user for their U-FQDN for
authentication.
To add an external user group object:
1.
In the navigation tree, select
Object Manager > User Objects > External User Groups
.
In the main display area, click the Add icon and select
New
to display the New External
Group dialog box.
2.
Enter a name for the external user group. The name must match the name of the
user group as configured on the external server.
3.
Enter a color and comment for the external user group.
4.
Configure the authentication methods for the user group:
•
XAuth. Enables XAuth authentication for the user group.
•
Auth. Enables local authentication against a username and password stored in a
security device's local database.
NOTE:
All passwords handled by NSM are case-sensitive.
•
L2TP. Enables authentication in the L2TP tunnel that users in the group use to
connect to the device.
5.
Click
OK
to save the new group.
Using Radius with User Groups
In this example, you configure an external RADIUS auth server named radius1 and define
an external auth user group named auth_grp2. You define the external auth user group
auth_grp2 in two places: External RADIUS auth server “ radius1,” and in NSM. For the
RADIUS server, you enter the IP address 10.20.1.100 and change its port number from the
default port number (1645) to 4500.
Next, you populate the auth user group “ auth_grp2” with auth users on the RADIUS server
only, leaving the group unpopulated in NSM. The members in this group are accountants
who require exclusive access to a server at IP address 10.1.1.80. You create an address
book entry for the server and name the address “ midas.” Finally, you configure a security
policy that permits only authenticated traffic from auth_grp2 to midas, both of which are
in the Trust zone.
401
Copyright © 2010, Juniper Networks, Inc.
Chapter 8: Configuring Objects
Содержание NETWORK AND SECURITY MANAGER 2010.3
Страница 6: ...Copyright 2010 Juniper Networks Inc vi...
Страница 36: ...Copyright 2010 Juniper Networks Inc xxxvi Network and Security Manager Administration Guide...
Страница 52: ...Copyright 2010 Juniper Networks Inc 2 Network and Security Manager Administration Guide...
Страница 90: ...Copyright 2010 Juniper Networks Inc 40 Network and Security Manager Administration Guide...
Страница 144: ...Copyright 2010 Juniper Networks Inc 94 Network and Security Manager Administration Guide...
Страница 146: ...Copyright 2010 Juniper Networks Inc 96 Network and Security Manager Administration Guide...
Страница 234: ...Copyright 2010 Juniper Networks Inc 184 Network and Security Manager Administration Guide...
Страница 310: ...Copyright 2010 Juniper Networks Inc 260 Network and Security Manager Administration Guide...
Страница 364: ...Copyright 2010 Juniper Networks Inc 314 Network and Security Manager Administration Guide...
Страница 366: ...Copyright 2010 Juniper Networks Inc 316 Network and Security Manager Administration Guide...
Страница 478: ...Copyright 2010 Juniper Networks Inc 428 Network and Security Manager Administration Guide...
Страница 576: ...Copyright 2010 Juniper Networks Inc 526 Network and Security Manager Administration Guide...
Страница 580: ...Copyright 2010 Juniper Networks Inc 530 Network and Security Manager Administration Guide...
Страница 592: ...Copyright 2010 Juniper Networks Inc 542 Network and Security Manager Administration Guide...
Страница 684: ...Copyright 2010 Juniper Networks Inc 634 Network and Security Manager Administration Guide...
Страница 690: ...Copyright 2010 Juniper Networks Inc 640 Network and Security Manager Administration Guide...
Страница 696: ...Copyright 2010 Juniper Networks Inc 646 Network and Security Manager Administration Guide...
Страница 698: ...Copyright 2010 Juniper Networks Inc 648 Network and Security Manager Administration Guide...
Страница 748: ...Copyright 2010 Juniper Networks Inc 698 Network and Security Manager Administration Guide...
Страница 778: ...Copyright 2010 Juniper Networks Inc 728 Network and Security Manager Administration Guide...
Страница 870: ...Copyright 2010 Juniper Networks Inc 820 Network and Security Manager Administration Guide...
Страница 872: ...Copyright 2010 Juniper Networks Inc 822 Network and Security Manager Administration Guide...
Страница 898: ...Copyright 2010 Juniper Networks Inc 848 Network and Security Manager Administration Guide...
Страница 908: ...Copyright 2010 Juniper Networks Inc 858 Network and Security Manager Administration Guide...
Страница 910: ...Copyright 2010 Juniper Networks Inc 860 Network and Security Manager Administration Guide...
Страница 995: ...PART 6 Index Index on page 947 945 Copyright 2010 Juniper Networks Inc...
Страница 996: ...Copyright 2010 Juniper Networks Inc 946 Network and Security Manager Administration Guide...