Q-Flex Satellite Modem Installation and Operating Handbook
6-30
Note for RADIUS Network Administrators
The modem RADIUS authentication feature will work out-of-the-box,
subject to the modem having access to a RADIUS server on the user’s
network. By default, all authorised users will receive administrator
privileges. If you want some users to get administrator access and some
view-only access then customisation of the RADIUS server configuration is
required as explained below.
The standard RADIUS Access-Accept response from the RADIUS server
can have an optional field added to it in order to distinguish between
administrator and view-only user login authorisation. This involves the
addition of a vendor-specific attribute using an SMI network management
private enterprise code of 64534 (to denote Teledyne Paradise Datacom),
which is one of a range reserved for private use. A vendor-specific
attribute named ‘Access-Level’ is used, where a value of 0 equates to
‘Modem Administrator’ and a value of 1 equates to ‘Modem User’ (view-
only). If the modem receives an Access-Accept response with no Access-
Level attribute, or with an Access-Level value that is not supported, then
the modem will default to administrator access being granted. The full
specification of this attribute of the Access-Accept response is as follows:
a.
Type: (one byte) value 0x1A - indicates a vendor-
specific attribute.
b.
Length: (one byte) value 0x09 – indicates the entire
vendor-specific attribute field is nine bytes in length.
c.
Vendor ID: (four bytes) 0x0000FC16 – indicates
Paradise private-use.
d.
Vendor type: (one byte) value 0x01 – indicates the
vendor-specific attribute is ‘Access-Level’.
e.
Vendor length: (one byte) value 0x03 – indicates the
remainder of the vendor-specific attribute field following
the Vendor ID is three bytes in length.
f.
Vendor data: (one byte) value 0=‘Modem Administrator’;
value 1=‘Modem User’ – indicates the authorised login
access level.
6.2.6.4 RADIUS Authentication Validity
Range:
5 to 60 minutes; step size: 1 minute
Description:
Controls the period between automatic re-authentication of the connection
to the RADIUS server. This is done in the background and no user
intervention is necessary unless the connection to the RADIUS server has
failed, when the user may be prompted to log in again using the fallback
RADIUS server (or standard modem log in if no RADIUS server is
available).
Table 6-35 RADIUS Authentication Validity