Creating Administrator Profiles On The Radius Server; Supported Radius Attributes - Colubris Networks CN3000 Administrator's Manual

Table of Contents

Advertisement

Chapter 7 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Customizing CN3000 and customer settings - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Chapter 7

Creating administrator profiles on the RADIUS server

If you want to support multiple administrator names and passwords, you must use a
RADIUS server to manage them. The CN3000 only supports a single admin name and
password internally.
Important: Improper configuration of the administrator profile could expose the CN3000
to access by any customer with a valid account. The only thing that distinguishes an
administrative account from that of a standard customer account is the setting of the
service type. Make sure that a customer is not granted access if service type is not
Administrative,
This is the reason why it may be prudent to use RADIUS Server 2 to handle
administrator logins. This practice reduces the risk of a bad configuration on the
RADIUS server side creating a security hole.
Supported
Admin Access Request
RADIUS
• User-Name (string): The name assigned to the administrator.
• NAS-Identifier (string): The NAS ID set on the Security > RADIUS page for the profile
attributes
• Service-Type (32-bit unsigned integer): As defined in RFC 2865. Set to a value of 6,
• Framed-MTU (32-bit unsigned integer): Hard-coded value of 1496. The value is
• MSCHAP-Challenge (string): As defined in RFC 2433. Only present when the
• MSCHAP-Response (string): As defined in RFC 2433. Only present when the
Admin Access Accept
• None supported.
Admin Access Reject
• None supported
Admin Access Challenge
• None supported
Admin Accounting Request
• Not supported
Admin Accounting Response
• Not supported
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - 172 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
being used.
which indicates SERVICE_TYPE_ADMINISTRATIVE.
always four bytes lower than the wireless MTU maximum which is 1500 bytes in order
to support IEEE802dot1x authentication.
authentication scheme on the Security > RADIUS page is set to MSCHAPv1 or
MSCHAPv2. Length = 8 bytes.
authentication scheme on the Security > RADIUS page is set to MSCHAPv1. Length
= 49 bytes.

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents