Avaya P580 User Manual page 128

Multiservice switches
Hide thumbs Also See for P580:
Table of Contents

Advertisement

Chapter 4
Realms
Groups and VSA
4-20
A Realm provides a mechanism by which a RADIUS manager can organize
user accounts. Consult the RADIUS vendor's documentation on how to
create Realms on the server. Once created, user accounts are placed in the
realms. The realm name is also configured on the NADs and when the
NADs send Access Request messages, the user name is appended with an
"@" and the Realm name.
For example: User Bob in the AvayaRealm would log into the switch with
Bob. The Avaya switch would send the Access Request message with user
Bob@AvayaRealm. The RADIUS server, upon receiving the request, would
look for Bob in the AvayaRealm.
In order to provide user accounts with the same granularity of privileges as
on the Avaya switch, Vendor Specific Attributes (VSA) must be configured
on the RADIUS server and a Group name must be set on the Avaya switch.
When set, the Group name is sent along with the Access Request message
to the RADIUS server.
The RADIUS server will send an Access Accept message if the user name,
password, and Group name match that of the user account. If so, the Access
Accept message will include the VSAs that identify the privileges the user
has.
* Note: If a user has a Standard RADIUS account, one that does not
contain the Group name, the RADIUS server will still respond
with an Access Accept message; but the message will not
contain the Group name or the VSAs. This is a security
loophole. See the Switch-Service-Type-Required parameter
below for more information
Avaya Service-Types specify the level of privileges a user has. The
following three types are supported:
Administrative (can create user accounts and configure the Avaya
switch)
Read-Write (can configure the Avaya switch)
Read-Only (can view the Avaya switch configuration)
Avaya Management Types specify what method the user can use to manage
the switch. The following four types are supported:
Avaya Management All
Avaya Local CLI (Serial port on the supervisor)
Avaya Remote CLI (Telnet session)
Avaya Web Agent
User Guide for the Avaya P580 and P882 Multiservice Switches, v6.0

Advertisement

Table of Contents
loading

This manual is also suitable for:

P882

Table of Contents