Figure 370 Radius Example: Keywords For User Attributes; User Groups; Access Users And The Zywall; Force User Authentication Policy - ZyXEL Communications Unified Security Gateway ZyWALL 300 User Manual

Unified security gateway
Hide thumbs Also See for Unified Security Gateway ZyWALL 300:
Table of Contents

Advertisement

Figure 370 RADIUS Example: Keywords for User Attributes

type=user;leaseTime=222;reauthTime=222
34.1.2.2 Creating a Large Number of Ext-User Accounts
If you plan to create a large number of Ext-User accounts, you might use CLI commands,
instead of the web configurator, to create the accounts. Extract the user names from the LDAP
or RADIUS server, and create a shell script that creates the user accounts. See
page 615
for more information about shell scripts.

34.1.3 User Groups

Use user groups when you want to create the same rule for several user accounts, instead of
creating separate rules for each one. User groups may consist of user accounts or other user
groups, but you cannot put access users and admin users in the same user group.
You cannot put access users and admin users in the same user group.
In addition, you cannot put the default admin account into any user group.
You cannot put the default admin account into any user group.
The sequence of members in a user group is not important.

34.1.4 Access Users and the ZyWALL

By default, access users do not have to log in to the ZyWALL to use the network services it
provides. The ZyWALL automatically routes packets for everyone. In this case, the ZyWALL
does not enforce any user-aware policies, but you can still set up policies based on IP address
or other criteria.
If you want to enforce user-aware policies, access users must log in to the ZyWALL first. In
this case, they should go to the appropriate IP address (or domain name, if you set up DNS) to
log in to the ZyWALL. (See
this by preventing access users from using network services until they log in.

34.1.5 Force User Authentication Policy

Instead of making users to go to the Login screen manually, you can configure the ZyWALL
to display the Login screen automatically whenever it routes HTTP traffic for anyone who has
not logged in yet. Then, the ZyWALL can enforce user-aware policies.
ZyWALL USG 300 User's Guide
Section 34.5 on page
513.) You can provide an incentive to do
Chapter 34 User/Group
Chapter 45 on
505

Advertisement

Table of Contents
loading

Table of Contents