User-Aware Access Control Example - ZyXEL Communications USG40 User Manual

Zywall/usg series
Hide thumbs Also See for USG40:
Table of Contents

Advertisement

Table 161 Configuration > Web Authentication > General > Add Authentication Policy (continued)
LABEL
Authentication
Single Sign-on
Force User
Authentication
OK
Cancel

20.2.1 User-aware Access Control Example

You can configure many policies and security settings for specific users or groups of users. Users
can be authenticated locally by the ZyWALL/USG or by an external (RADIUS) authentication server.
In this example the users are authenticated by an external RADIUS server at 172.16.1.200. First,
set up the user accounts and user groups in the ZyWALL/USG. Then, set up user authentication
using the RADIUS server. Finally, set up the policies in the table above.
20.2.1.1 Set Up User Accounts
Set up user accounts in the RADIUS server. This example uses the Web Configurator. If you can
export user names from the RADIUS server to a text file, then you might configure a script to
create the user accounts instead.
Click Configuration > Object > User/Group > User. Click the Add icon.
1
Enter the same user name that is used in the RADIUS server, and set the User Type to ext-user
2
because this user account is authenticated by an external server. Click OK.
Chapter 20 Web Authentication
DESCRIPTION
Select the authentication requirement for users when their traffic matches this policy.
unnecessary - Users do not need to be authenticated.
required - Users need to be authenticated. If Force User Authentication is selected, all
HTTP traffic from unauthenticated users is redirected to a default or user-defined login
page. Otherwise, they must manually go to the login screen. The ZyWALL/USG will not
redirect them to the login screen.
This field is available for user-configured policies that require Single Sign-On (SSO). Select
this to have the ZyWALL/USG enable the SSO feature. You can set up this feature in the
SSO screen.
This field is available for user-configured policies that require authentication. Select this to
have the ZyWALL/USG automatically display the login screen when users who have not
logged in yet try to send HTTP traffic.
Click OK to save your changes back to the ZyWALL/USG.
Click Cancel to exit this screen without saving.
ZyWALL/USG Series User's Guide
439

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents