Chapter 2 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - How it works - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Chapter 2
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - 28 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Account policy
To maintain the integrity of the configuration settings, only one administrator can be
connected to the management tool at a given time. To prevent the management tool
from being locked up by an idle user, two mechanisms are in place:
• If a user’s connection to the management tool remains idle for more than ten minutes,
the CN3000 automatically logs the user out.
• If a second user connects to the management tool and logs in with the correct
username and password, the first user’s session is terminated. If required, you can
disable this mechanism on the
Management > Management tool
page.
Validating administrator logins using a RADIUS server
You can use a RADIUS server to authenticate logins to the management tool. One
advantage of this is that it enables you to create several administrator accounts, each
with its own username and password.
Important:
Make sure that the RADIUS profile you select is configured and that the
administrator account is defined on a functioning RADIUS server. If not, you will not be
able to log back into the CN3000 because the administrator password cannot be
authenticated.
To setup RADIUS authentication, do the following:
1.
On the main menu, click
Security
then click
RADIUS.
2.
Click
Add a New Profile
.
3.
Define the settings for the RADIUS profile you want to use to validate administrator
logins. Either use an existing profile or add a new profile.
4.
Click
Save
.
5.
On the main menu, click
Management
, then click
Management tool
.
6.
In the
Administrator authentication
box select the RADIUS profile you defined in
step 3.
7.
Click
Save
.
Security
To maintain the integrity of the configuration settings, only one user can be connected to
the management tool at a given time. To prevent the management tool from being
locked up by an idle user, two mechanisms are in place:
• If a user’s connection to the management tool remains idle for more than ten minutes,
the CN3000 automatically logs the user out.
• If a second user connects to the management tool and logs in with the correct
username and password, the first user’s session is terminated. If required, you can
disable this mechanism on the
Management > Management tool
page.
HTTPS
Communications between the management station and the CN3000 occurs via HTTPS.
Before logging onto the management tool, users must accept a Colubris Networks
certificate. You can replace this certificate with your own. For more information see,
Chapter 10
.
Summary of Contents for CN3000
Page 1: ...CN3000 Administrator s Guide...
Page 8: ...Table of Contents 8...
Page 60: ...Chapter 2 How it works Chapter 2 60...
Page 94: ...Chapter 4 Scenarios Chapter 4 94...
Page 106: ...Chapter 5 Activating the public access interface Chapter 5 106...
Page 211: ...Chapter 10 SSL certificates Chapter 10 211...
Page 292: ...Chapter 13 The configuration file Chapter 13 292...
Page 370: ...Chapter 16 Sample setup Microsoft RADIUS Chapter 16 370...
Page 396: ...Chapter 16 Sample setup Microsoft RADIUS Chapter 16 396...
Page 414: ...Chapter 17 Experimenting with NOC authentication Chapter 17 414...