Tavve zoneranger User Manual page 106

Table of Contents

Advertisement

For the purposes of this example, assume that all DMZ devices are in the 10.1.1.0/255.255.255.0
subnet, that access to the router (10.1.1.1) and the two ZoneRangers (10.1.1.100 and 10.1.1.101) are
to be authenticated and authorized through servers acs1 and acs2, using TACACS+ only, and that all
other devices are to use acs3 and acs4, and may use TACACS+ or RADIUS. It will also be assumed
that source address spoofing will be used when relaying requests to acs1 and acs2, but will not be
used for acs3 and acs4.
In order to support this scenario, the following configuration would be required:
1. On both ZoneRangers, define the following server groups:
2. On both ZoneRangers, define the following TACACS+ proxy rules:
3. On both ZoneRangers, define the following RADIUS proxy rule:
4. On acs1 and acs2, enable source address spoofing for TACACS+. In addition, the GVI or
RGVI service should be enabled and configured to intercept traffic destined for
10.1.1.0/255.255.255.0
5. On rg3 and rg4, ensure that source address spoofing for TACACS+ and RADIUS is
disabled.
Additional Configuration Options
In order to troubleshoot any difficulties associated with the use of TACACS+ or RADIUS proxy
services, the ZoneRanger can be configured to log all TACACS+ and/or RADIUS transactions.
TACACS+ logging is configured on the Configuration -> Access Control page TACACS+ tab on
the ZoneRanger web interface, and RADIUS logging is configured on the RADIUS tab.
In addition, a number of advanced configuration settings are provided for each protocol. For
TACACS+ the available settings are:
Client timeout – the amount of time, in seconds, that the ZoneRanger will maintain
information about an inactive TACACS+ authentication or authorization session.
Server timeout – the amount of time that the Ranger Gateway will wait for a response
from a TACACS+ server.
Maximum Message Size – the maximum size, in bytes, of a valid TACACS+ message.
For RADIUS, the available settings are:
ZoneRanger 5.5 User's Guide
serverGroup1:
acs1 acs1
acs2 acs2
serverGroup2:
rg3 acs3
rg4 acs3
rg3 acs4
rg4 acs4
10.1.1.1 serverGroup1
10.1.1.[100-101] serverGroup1
*.*.*.* serverGroup2
*.*.*.* serverGroup2
.
106

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents