S
ECURITY
M
ANAGEMENT
P
ACKET
L
IGHT
N
ETWORKS
PL-1000RO
3.3
I
NSTALLATION AND
C
ONFIGURATION
M
ANUAL
C
ONFIDENTIAL AND
P
ROPRIETARY
I
NFORMATION
.
A
LL RIGHTS RESERVED
.
P
AGE
38
4.2.1
Local Authentication
The local authentication method is always enabled. The authentication is
performed against a local database stored in the node.
Local authentication requires that an updated list of user names and passwords
be provided to each node in the network.
4.2.2
Remote Authentication
The PL-1000RO supports centralized authentication, implemented with the
Radius protocol as defined by RFC-2865.
The remote authentication method is optional, and can be enabled or disabled by
the network administrator. The authentication is performed against a centralized
database stored on a Radius server.
The remote authentication allows the network administer to keep the updated list
of user names and passwords on a Radius server.
When a user tries to log in and the user name and password are not on the local
user list, if the Radius authentication is enabled, the node communicates with the
Radius server and performs remote user authentication. If the user name and
password are on the remote user list, the log in succeeds.
4.2.2.1
Attribute Value Pairs
The Radius Attribute Value Pairs (AVP) carry data in both the request and the
response for the authentication.
The following table lists the attributes used by the remote Radius authentication.
Table 5: Attributes Used
Attribute
AVP Type Access-Request
Access-Accept
Format/Values
User-Name
1
√
√
The name of the user as
carried by the Radius
Access-Request
.
Format: String
User-Password 2
√
√
The password of the user
as carried by the Radius
Access-Request
.
Format: String
Class
25
-
√
The access level granted
to the user as carried by
the Radius
Access-Accept
.
Format: String
Allowed values:
•
1
: read-only access
•
2
: read-write access
•
4
: admin access