GE C30 Instruction Manual page 126

Ur series
Hide thumbs Also See for C30:
Table of Contents

Advertisement

5.2 PRODUCT SETUP
To use local authentication:
1.
Log in as outlined (Administrator or Supervisor, then Observer).
2.
After making any required changes, log off using the Commands > Relay Maintenance > Security menu.
logged in through the front panel log out by logging in as None.
Users logged in through the front panel are not timed out and cannot be forcefully logged out by a
supervisor. Roles logged in through the front panel that do no allow multiple instances (Administrator,
Supervisor, Engineer, Operator) must switch to None (equivalent to a logout) when they are done in
order to log out.
To configure remote authentication:
1.
In the EnerVista software, choose device authentication and log in as Administrator.
2.
Configure the following RADIUS server parameters: IP address, authentication port, shared secret, and vendor ID. The
following procedure outlines how to set up a simple RADIUS server, where the third-party tool used is an example.
a. Download and install
b. In the RADIUSD.CONF file, locate the "bind_address" field and enter your RADIUS server IP address.
c. In the USERS.CONF file in the <Path_to_Radius>\etc\raddb folder, add the following text to configure a user "Tes-
ter" with an Administrator role.
Tester:
->User-Password == "Testing1!1"
->GE-UR-Role = Administrator
d. In the CLIENTS.CONF file in the <Path_to_Radius>\etc\raddb folder, add the following text to define a RADIUS cli-
5
ent, where the client IP address is 10.0.0.2, the subnet mask is 255.255.255.0, the shared secret specified here is also
configured on the UR device for successful authentication, and the shortname is a short, optional alias that can be
used in place of the IP address.
client 10.0.0.2/24 {
secret = testing123
shortname = private-network-1
}
e. In the <Path_to_Radius>\etc\raddb folder, create a file called dictionary.ge and add the following content.
# ##########################################################
# GE VSA's
############################################################
VENDOR
# Management authorization
BEGIN-VENDOR
# Role ID
ATTRIBUTE
# GE-UR-ROLE values
VALUE GE-UR-Role
VALUE GE-UR-Role
VALUE GE-UR-Role
VALUE GE-UR-Role
5-10
FreeRADIUS
as the RADIUS server.
GE
2910
GE
GE-UR-Role
1
Administrator
1
Supervisor
2
Engineer
3
Operator
4
C30 Controller System
integer
5 SETTINGS
Users
GE Multilin

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents