User authentication
Remote Authentication Dial-In User Service (RADIUS)
LR54 User Guide
817
servers are unavailable. Additionally, users who are configured locally but are not configured on the
RADIUS server are still able to log into the device. Authentication methods are attempted in the order
they are listed until the first successful authentication result is returned; therefore if you want to
ensure that users are authenticated first through the RADIUS server, and only authenticated locally if
the RADIUS server is unavailable or if the user is not defined on the RADIUS server, then you should
list the RADIUS authentication method prior to the Local users authentication method.
See
for more information about authentication methods.
If the RADIUS servers are unavailable and the LR54 device falls back to local authentication, only users
defined locally on the device are able to log in. RADIUS users cannot log in until the RADIUS servers
are brought back online.
Configure your LR54 device to use a RADIUS server
This section describes how to configure a LR54 device to use a RADIUS server for authentication and
authorization.
Required configuration items
n
Define the RADIUS server IP address or domain name.
n
Define the RADIUS server shared secret.
n
Add RADIUS as an authentication method for your LR54 device.
Additional configuration items
n
Whether other user authentication methods should be used in addition to the RADIUS server,
or if the RADIUS server should be considered the authoritative login method.
n
The RADIUS server port. It is configured to 1812 by default.
n
Add additional RADIUS servers in case the first RADIUS server is unavailable.
n
The server NAS ID. If left blank, the default value is used:
l
If you are access the LR54 device by using the WebUI, the default value is for NAS ID is
httpd
.
l
If you are access the LR54 device by using ssh, the default value is
sshd
.
n
Time in seconds before the request to the server times out. The default is 3 seconds and the
maximum possible value is 60 seconds.
n
Enable additional debug messages from the RADIUS client.
Web
1. Log into Digi Remote Manager, or log into the local Web UI as a user with full Admin access
rights.
2. Access the device configuration:
Remote Manager:
a. Locate your device as described in
Use Digi Remote Manager to view and manage your
b. Click the
Device ID
.
c. Click
Settings
.
d. Click to expand
Config
.