To delete a RADIUS server:
Click the Remove link next to the RADIUS server you want to delete.
The RADIUS server is deleted.
To configure remote access permissions for users defined in the RADIUS server:
1. Click permissions for RADIUS users.
2. Select or clear the Enable RADIUS authentication for remote access users checkbox.
3. When selected, choose which users are given remote access permissions:
•
To allow all users defined in the RADIUS server to authenticate - Select All users defined
on RADIUS server
•
Specific user groups defined in the RADIUS server - Select For specific RADIUS groups
only and enter in the text field the names of the user groups separated by commas.
•
To allow administrators with Read-only permissions to authenticate - Select Read-only
Administrators
4. Click Apply.
To add an Active Directory domain:
1. In the Active Directory section, click New.
The Add new Domain window opens.
2. Enter this information:
•
Domain - The domain name.
•
IP address - The IP address of one of the domain controllers of your domain.
Note - 1100 appliances only support IPv4 addresses. 1200r and 1400 appliances support
both IPv4 and IPv6 addresses.
•
User name - The user must have administrator privileges to ease the configuration process
and create a user based policy using the users defined in the Active Directory.
•
Password - The user's password. You cannot use these characters when you enter a
password or shared secret: { } [ ] ` ~ | ' " # + \
•
User DN - Click Discover for automatic discovery of the DN of the object that represents
that user or enter the user DN manually. For example: CN=John
James,OU=RnD,OU=Germany,O=Europe,DC=Acme,DC=com
3. Select Use user groups from specific branch only if you want to use only part of the user
database defined in the Active Directory. Enter the branch in the Branch full DN in the text
field.
4. Click Apply.
Once an Active Directory is defined, you can select it from the table and choose Edit or Delete
when necessary.
When you edit, note that the Domain information is read-only and cannot be changed.
When you add a new Active Directory domain, you cannot create another object using an existing
domain.
Check Point 1100/1200R/1400 Appliances Centrally Managed Administration Guide R77.20.70
Appliance Configuration
|
99
Need help?
Do you have a question about the CHECK POINT 1100 and is the answer not in the manual?