Management Advanced Settings - D-Link NetDefendOS User Manual

Network security firewall
Hide thumbs Also See for NetDefendOS:
Table of Contents

Advertisement

authsource=RADIUS server_ip=192.168.1.1 server_port=80
client_ip=192.168.1.30 client_port=5987
The Local Console is a Fallback Option
It is possible that the administrator could be locked out from logging on via the Web Interface or
the CLI over SSH because a RADIUS server will not authenticate the entered credentials and the
local database is not allowed to do it either. In such cases, the local console port on the
NetDefend Firewall can still be used for management access. However, if the password has been
set for the local console then that password must still be given to get CLI management access
(note that the console password is totally separate from other management passwords).
Example 2.10. Enabling RADIUS Management Authentication
This example will change the current default rule for Web Interface management access so that
authentication is performed using two RADIUS servers. It is assumed that the RADIUS server
objects are already defined in the configuration and have the names radius_auth1 and
radius_auth2 where radius_auth2 is the fallback server in case the other fails to respond.
The Authentication Order will be set to Local First which will mean that the local NetDefendOS
database will be consulted first. If the user is not found there then the RADIUS servers will be
queried.
All users who are members of the group sys_admins are allowed full access privileges. All other
authenticated users will have audit privileges only.
Command-Line Interface
gw-world:/> set RemoteManagement RemoteMgmtHTTP rmgmt_http
Web Interface
1.
Go to: System > Device > Remote Management
2.
Select the rmgmt_http object so that its properties can be edited
3.
Set Authentication Source to RADIUS
4.
Set Authentication Order to Local First
5.
For RADIUS Server, select radius_auth1 and press Include
6.
Repeat the preceding step, selecting radius_auth2
7.
Set Admin Groups to be sys_admins
8.
Click OK

2.1.10. Management Advanced Settings

Chapter 2: Management and Maintenance
AuthSource=RADIUS
AuthOrder=LocalFirst
RadiusServers=radius_auth1,radius_auth2
AdminGroups=sys_admins
70

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents