Alcatel-Lucent 7450 System Management Manual page 24

Ethernet service switch
Hide thumbs Also See for 7450:
Table of Contents

Advertisement

Authentication
Application Specific Behavior
Operator Management
The server access mode is fixed to Round-Robin (Direct cannot be configured for operator
management). A health-check function is available for operator management, which can
optionally be disabled. The health-check polls the server once every 10 seconds with an
improbable user name. If the server does not respond to this health-check, it will be marked
down.
If the first server in the list cannot find a user, the next server in the RADIUS server list is not
queried and access is denied. If multiple RADIUS servers are used, it is assumed they all have
the same user database.
RADIUS Authentication
If the first server in the list cannot find a user, the next server in the RADIUS server list is not
queried and access is denied. If multiple RADIUS servers are used, it is assumed they all have
the same user database.
RADIUS Challenge/Response Interactive Authentication
Challenge-response interactive authentication is used for key authentication where the Radius
server is asking for the valid response to a displayed challenge. The challenge packet includes
a challenge to be displayed to the user, such as a unique generated numeric value unlikely ever
to be repeated. Typically this is obtained from an external server that knows what type of
authenticator is in the possession of the authorized user and can therefore choose a random or
non-repeating pseudorandom number of apropriate length.
The user then enters the challenge into his device (or software) and it calculates a response,
which the user enters into the client which forwards it to the RADIUS server via an access
request. If the response matches the expected response, the RADIUS server allows the user
access, otherwise it rejects the response.
RADIUS challenge/response mode is enabled using the CLI interactive-authentication
command in the config>system>security>radius context. RADIUS interactive authentication
is disabled by default. The option needs to be enabled via CLI.
Enabling interactive authentication under CLI does not mean that the system uses RADIUS
challenge/response mode by default. The configured password authentication-order parameter
is used. If the authentication-order parameter is local RADIUS, the system will first attempt to
Page 24
7450 ESS System Mangement Guide

Advertisement

Table of Contents
loading

Table of Contents