RUGGEDCOM ROX II
CLI User Guide
Chapter 6
Security
Configuring RADIUS Authentication for LOGIN Services
139
Attribute
Value
String: RuggedCom
A RADIUS server may also be used to authenticate access on ports with IEEE 802.1x security enabled. When this is
required, the following attributes are sent by the RADIUS client to the RADIUS server:
Attribute
Value
User-Name
{ The user name as derived from the client's EAP identity response }
NAS-IP-Address
{ The Network Access Server IP address }
Service-Type
2
Frame-MTU
1500
EAP-Message
a
{ A message(s) received from the authenticating peer }
a
EAP-Message is an extension attribute for RADIUS, as defined by
[http://freeradius.org/rfc/rfc2869.html#EAP-Message].
Primary and secondary RADIUS servers, typically operating from a common database, can be configured for
redundancy. If the first server does not respond to an authentication request, the request will be forwarded to the
second server until a positive/negate acknowledgment is received.
NOTE
RADIUS authentication activity is logged to the authentication log file
var/log/auth.log
. Details
of each authentication including the time of occurrence, source and result are included. For more
information about the authentication log file, refer to
Section 4.10.1, “Viewing Logs”
.
RUGGEDCOM ROX II supports RADIUS authentication for the LOGIN and PPP services. Different RADIUS servers can
be configured to authenticate both services separately or in combination.
The LOGIN services consist of the following access types:
• Local console logins via the serial port
• Remote shell logins via SSH and HTTPS
• Secure file transfers using HTTPS, SCP and SFTP (based on SSH)
Authentication requests for LOGIN services will attempt to use RADIUS first and any local authentication settings
will be ignored. Only when there is no response (positive/negative) from any of the configured RADIUS servers will
RUGGEDCOM ROX II authenticate users locally.
The PPP service represents incoming PPP connections via a modem. Authentication requests to the PPP service use
RADIUS only. In the event that no response is received from any configured RADIUS server, RUGGEDCOM ROX II
will not complete the authentication request.
CONTENTS
•
Section 6.7.3.1, “Configuring RADIUS Authentication for LOGIN Services”
•
Section 6.7.3.2, “Configuring RADIUS Authentication for PPP Services”
•
Section 6.7.3.3, “Configuring RADIUS Authentication for Switched Ethernet Ports”
Section 6.7.3.1
Configuring RADIUS Authentication for LOGIN Services
To configure RADIUS authentication for LOGIN services, do the following:
Содержание RUGGEDCOM ROX II
Страница 2: ...RUGGEDCOM ROX II CLI User Guide ii ...
Страница 4: ...RUGGEDCOM ROX II CLI User Guide iv ...
Страница 39: ...RUGGEDCOM ROX II CLI User Guide Table of Contents xxxix 19 5 VLANs 752 ...
Страница 40: ...Table of Contents RUGGEDCOM ROX II CLI User Guide xl ...
Страница 46: ...Preface RUGGEDCOM ROX II CLI User Guide xlvi Customer Support ...
Страница 96: ...Chapter 2 Using RUGGEDCOM ROX II RUGGEDCOM ROX II CLI User Guide 50 Accessing Maintenance Mode ...
Страница 170: ...Chapter 5 System Administration RUGGEDCOM ROX II CLI User Guide 124 Deleting a Scheduled Job ...
Страница 256: ...Chapter 6 Security RUGGEDCOM ROX II CLI User Guide 210 Enabling Disabling a Firewall ...
Страница 402: ...Chapter 11 Wireless RUGGEDCOM ROX II CLI User Guide 356 Managing Cellular Modem Profiles ...
Страница 646: ...Chapter 13 Unicast and Multicast Routing RUGGEDCOM ROX II CLI User Guide 600 Deleting a Multicast Group Prefix ...
Страница 732: ...Chapter 15 Network Discovery and Management RUGGEDCOM ROX II CLI User Guide 686 Viewing NETCONF Statistics ...
Страница 790: ...Chapter 17 Time Services RUGGEDCOM ROX II CLI User Guide 744 Deleting a Broadcast Multicast Address ...