Example: Configuring Role-Based Administration
Copyright © 2010, Juniper Networks, Inc.
You can designate a default RADIUS authentication server for the global domain and for
each subdomain. The default authentication server is used:
To authenticate administrators when they log into the NSM system
To authenticate RAS users in VPNs
For step-by-step instructions on configuring a RADIUS authentication server to
authenticate administrators and users, see the Network and Security Manager Online Help
topic "Editing the Domain Contact."
In this example, you configure a domain structure for an Internet service provider (ISP)
with a co-location facility in New York that handles customers across four states. The
company uses a two-letter state postal code combined with the customer name. That
ISP's goal is to manage all devices and policies from the co-location facility and provide
read-only permission for customers to view log entries and generate reports. No VPNs
are used.
To configure this domain structure, use the following process:
Create the subdomains.
Create the subdomain administrators.
Create the read-only customer administrator.
Log in as each administrator (for verification).
Step 1: Create the Subdomains
In this step, you create a subdomain for each company that uses the ISP.
Log in to the global domain as the super administrator.
1.
From the Menu bar, select Tools > Manage Administrators and Domains.
2.
Click the Subdomains tab, then click the Add icon to create a subdomain for the
3.
first customer. Configure the following four subdomains:
MA_company1
NH_company2
RI_company3
VT_company4
Click OK to save your changes.
4.
Step 2: Create the Subdomain Administrator
In this step, you create a subdomain administrator with full permissions for the domain.
Chapter 3: Configuring Role-Based Administration
91
Need help?
Do you have a question about the NETWORK AND SECURITY MANAGER 2010.2 - ADMINISTRATION GUIDE REV1 and is the answer not in the manual?
Questions and answers