Siemens SIMATIC NET SCALANCE S615 Configuration Manual page 41

Industrial ethernet security web based management
Hide thumbs Also See for SIMATIC NET SCALANCE S615:
Table of Contents

Advertisement

RADIUS authorization mode "SiemensVSA"
Requirement
For the RADIUS authorization mode "Siemens VSA" the following needs to be set on the
RADIUS server:
● Manufacturer code: 4196
● Attribute number: 1
● Attribute format: Character string (group name)
Procedure
If you have set the authorization mode "SiemensVSA", the authentication of users via a
RADIUS server runs as follows:
1. The user logs on with user name and password on the device.
2. The device sends an authentication request with the login data to the RADIUS server.
3. The RADIUS server runs a check and signals the result back to the device.
Case A: The RADIUS server reports a successful authentication and returns the group
assigned to the user to the device.
– The group is known on the device and the user is not entered in the table "External User
– The group is known on the device and the user is entered in the table "External User
– The group is not known on the device and the user is entered in the table "External User
– The group is not known on the device and the user is not entered in the table "External
Case B: The RADIUS server reports a successful authentication but does not return a group
to the device.
– The user is entered in the table "External User Accounts":
– The user is not entered in the table "External User Accounts":
Case C: The RADIUS server reports a failed authentication to the device:
– The user is denied access.
SCALANCE S615 Web Based Management
Configuration Manual, 11/2019, C79000-G8976-C388-08
Accounts"
→ The user is logged in with the rights of the assigned group.
Accounts"
→ The user is assigned the role with the higher rights and logged in with these rights.
Accounts"
→ The user is logged in with the rights of the role linked to the user account.
User Accounts"
→ The user is logged in with the rights of the role "Default".
→ The user is logged in with the rights of the linked role "".
→ The user is logged in with the rights of the role "Default".
Technical basics
3.5 Security functions
41

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents