Zhone IMACS 8000 User Manual page 217

Integrated access device
Table of Contents

Advertisement

CPU Card
"SERVER: the IP address of the RADIUS server
"FALLBACK: see explanation below
"PORT: UDP port that the RADIUS server uses to receive authentication packets from
its clients. The default is 1812.
"TIMEOUT: How many seconds the system will wait for a response from the RADIUS
server. The default is 3.
"RETRIES: The number of attempts that the IMACS will try to authenticate the
password if there is no response from the server. The default is 3.
"SECRET: This is the shared secret key between the IMACS and the RADIUS server.
The secret key is a case-sensitive text string up to 64 characters long. The secret key on
the server must match exactly the secret key on the IMACS. Along with alpha-numeric
characters, these special characters are also allowed: ~!@#$%^&*()_+|\=-'{}[]:"';<>?/.,
Fallback allows for access to the IMACS shelf from the console port should the RADIUS
server not respond for whatever reason. The IMACs will then process username and password
authentication locally, as if the RADIUS feature were not enabled. This is only true if
RADIUS is turned on, fallback is enabled and the RADIUS server cannot be reached.
WARNING!Saving the RADIUS setup without fallback will from that point on require the
RADIUS server to authenticate the user. Failure to have the server setup, or failure to be
able to reach the server will deny the user access to the node. Zhone Technologies or its
affiliates will not be able to grant access to the IMACS shelf.
For the server side, the following Vendor Specific Attributes (VSA) are required in order to
authenticate the IMACS Radius authentication request:
Vendor ID: 5504
Attribute: Zhone-IMACS-User-Group
The Zhone-IMACS-User-Group is an integer value ranging form 1-32 and this correlates to
the User Group Permissions as defined on the IMACS system.
When you define a user on the RADIUS server, you must also provide the
Zhone-IMACS-User-Group attribute associated with that user in order for the IMACS system
to pass the correct group privileges when the user logs into the system.
Following is an example from a FreeRADIUS server:
System Cards
CPU Card User Screens and Settings
7-7

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents