
Chapter 35 User/Group
UAG Series User’s Guide
400
Note: The default
admin
account is always authenticated locally, regardless of the
authentication method setting. (See
for more information
about authentication methods.)
Ext-User Accounts
Set up an
ext-user
account if the user is authenticated by an external server and you want to set
up specific policies for this user in the UAG. If you do not want to set up policies for this user, you
do not have to set up an
ext-user
account.
All
ext-user
users should be authenticated by an external server, such as RADIUS. If the UAG tries
to use the local database to authenticate an
ext-user
, the authentication attempt always fails.
(This is related to AAA servers and authentication methods, which are discussed in
and
, respectively.)
Note: If the UAG tries to authenticate an
ext-user
using the local database, the attempt
always fails.
Once an
ext-user
user has been authenticated, the UAG tries to get the user type (see
) from the external server. If the external server does not have the information, the
UAG sets the user type for this session to
User
.
For the rest of the user attributes, such as reauthentication time, the UAG checks the following
places, in order.
1
User account in the remote server.
2
User account (Ext-User) in the UAG.
3
Default user account for RADIUS users (
radius-users
) in the UAG.
See
Setting up User Attributes in an External Server on page 413
for a list of attributes and how to
set up the attributes in an external server.
Ext-Group-User Accounts
Ext-Group-User
accounts are similar to ext-user accounts but allow you to group users by the
value of the group membership attribute configured for the RADIUS server. See
for more on the group membership attribute.
Dynamic-Guest Accounts
Dynamic guest accounts are guest accounts, but are created dynamically and stored in the UAG’s
local user database. A dynamic guest account has a dynamically-created user name and password.
A dynamic guest account user can access the UAG’s services only within a given period of time and
will become invalid after the expiration date/time.
guest-manager
Create dynamic guest accounts
WWW
pre-subscriber
Access network services
Web Authentication Portal
dynamic-guest
Access network services
Web Authentication Portal
Table 177
Types of User Accounts (continued)
TYPE
ABILITIES
LOGIN METHOD(S)
Содержание UAG2100
Страница 171: ...Chapter 10 Interfaces UAG Series User s Guide 171 Figure 118 Configuration Network Interface PPP Add ...
Страница 185: ...Chapter 10 Interfaces UAG Series User s Guide 185 Figure 124 Configuration Network Interface Bridge Add ...
Страница 247: ...Chapter 19 UPnP UAG Series User s Guide 247 Figure 166 Network Connections My Network Places Properties Example ...
Страница 319: ...Chapter 26 Billing UAG Series User s Guide 319 Figure 226 Configuration Billing Payment Service Desktop View ...
Страница 320: ...Chapter 26 Billing UAG Series User s Guide 320 Figure 227 Configuration Billing Payment Service Mobile View ...
Страница 342: ...Chapter 30 IPSec VPN UAG Series User s Guide 342 Figure 242 Configuration VPN IPSec VPN VPN Connection Add Edit ...
Страница 349: ...Chapter 30 IPSec VPN UAG Series User s Guide 349 Figure 244 Configuration VPN IPSec VPN VPN Gateway Add Edit ...
Страница 365: ...Chapter 30 IPSec VPN UAG Series User s Guide 365 ...
Страница 507: ...Chapter 46 System UAG Series User s Guide 507 Figure 341 Configuration System WWW Login Page Desktop View ...
Страница 535: ...Chapter 47 Log and Report UAG Series User s Guide 535 Figure 375 Configuration Log Report Email Daily Report ...
Страница 539: ...Chapter 47 Log and Report UAG Series User s Guide 539 Figure 377 Configuration Log Report Log Settings Edit System Log ...
Страница 602: ...Appendix B Legal Information UAG Series User s Guide 602 Environmental Product Declaration ...