Selenio
TM
BNP User Guide, Release 3.7.1
49
- User Authentication Configuration
Figure 24.
Port Name Modified
New Port Name
User Authentication Configuration
The
User Authentication
tab provides a central area from which user control settings can be edited,
added, or deleted. The BNP permits both local and remote user authentication.
The BNP authenticates with an AAA server when the AAA feature is enabled from the BNP, using the
name and password provided by the user account during the login process. If the user name exists in
the AAA server and the password matches with that stored on the AAA server, the user authorization
level—as either
Admin
,
Operator
, or
User
—is then returned to the BNP (see also “User Account
•
Remote user authentication is performed using an authentication, authorization and accounting
(AAA) server that supports RADIUS or . The AAA server handles requests for access to
system resources to be configured, allowing maintenance of user profiles to be performed once for
any number of clients. When a client wants to access a system resource, it must first get permission
from the AAA server.
•
By default, the BNP provides a local user fallback authentication method that allows users to log in
when an AAA server is not available. However, for security and account management reasons, use
of AAA is recommended. All passwords configured for AAA—both remote and local—are
encrypted.
You can also create additional, customized user accounts which may be useful for authentication
and authorization where AAA is disabled on the BNP or when AAA servers are not reachable from
the BNP (as indicated by a timeout occurring for an authentication request to a AAA server).
The following work flow (
) illustrates the authentication process when a user attempts to log
in to the BNP.