38
| SmartNA-X Administration | SmartNA-X 1G/10G Modular
SmartNA-X
™
1G/10G User Guide 1.4
©
2015 Network Critical Solutions Limited
Figure 27: Add server window
Configuring RADIUS authentication servers
Remote Authorization Dial-In User Service (RADIUS) servers provide a centralized 802.1X or MAC-based network
access control. The device is a RADIUS client that can use a RADIUS server to provide centralized security.
An organization can establish a Remote Authorization Dial-In User Service (RADIUS) server to provide centralized
802.1X or MAC-based network access control for all of its devices. In this way, authentication and authorization can be
handled on a single server for all devices in the organization.
The device can act as a RADIUS client that uses the RADIUS server for the following services:
• Authentication—Provides authentication of regular and 802.1X users logging onto the device by using usernames and
user-defined passwords.
• Authorization—Performed at login. After the authentication session is completed, an authorization session starts using
the authenticated username. The RADIUS server then checks user privileges.
• Accounting—Enable accounting of login sessions using the RADIUS server. This enables a system administrator to
generate accounting reports from the RADIUS server.
RADIUS authentication servers can be configured using the
RADIUS authentication
dialog, shown below.
Figure 28: RADIUS authentication server list
RADIUS workflow
This device uses PAP (Password Authentication Protocol) when authenticating users with the RADIUS server. To use a
RADIUS server, do the following:
1.
Open an account for the device on the RADIUS server.
2.
In that server’s
radiusd.conf
configuration file, add users and configure the
Reply-Message
attribute so that it
contains “audit”, “user”, or “admin” for the respective Audit, Operator, and Administrator account. For example:
user1 Cleartext-Password := “User1Password
Reply-Message = "audit"
user2 Cleartext-Password := “User2Password
Reply-Message = "user"
user3 Cleartext-Password := “User3Password
Reply-Message = "admin"
3.
Specify RADIUS as the authentication method, so that when a user logs onto the device, authentication is performed
on the RADIUS server instead of locally.