Configuring A Securid Authentication Server - Juniper NETWORK AND SECURITY MANAGER 2010.3 - ADMINISTRATION GUIDE REV1 Administration Manual

Table of Contents

Advertisement

Network and Security Manager Administration Guide
396
The RADIUS server automatically receives the above information when you load the
Juniper Networks dictionary file onto it. To make new data entries, you must manually
enter a value in the form indicated by the attribute type.
Example: Configuring a Radius Auth Server
In the following example, you define an auth server object for a RADIUS server. You specify
its user account types as auth, L2TP, and XAuth. You name the RADIUS server " radius1"
and accept the ID number that the security device automatically assigns it. You enter its
IP address, which is 10.20.1.100; and change its port number from the default port number
(1645) to 4500. You define its shared secret as " A56htYY97kl" . You change the
authentication timeout value from the default (10 minutes) to 30 minutes and the RADIUS
retry timeout from 3 seconds to 4 seconds. You also assign its two backup servers the
IP addresses 10.20.1.110 and 10.20.1.120.
In addition, you load the Juniper Networks dictionary file on the RADIUS server so that it
can support queries for the following vendor-specific attributes (VSAs): user groups,
administrator privileges, remote L2TP and XAuth settings.
In the main navigation tree, select Object Manager > Authentication Servers and
1.
click the Add icon. Enter a name, color, and comment for the authentication server.
Configure the RADIUS servers:
2.
For Main Server, enter the IP 10.20.1.100
For Primary Backup Server, enter IP 10.20.1.110
For Secondary Backup Server, enter IP 10.20.1.120
For timeout, enter 30.
3.
Select the following:
4.
For Firewall Auth Users
For XAuth Users
For L2TP Users
For Server Type, select RADIUS.
5.
Configure the RADIUS server properties:
6.
For server port, enter 4500 (default is 1645)
For secret, enter A56hYY97kl
For retry timeout, select 4.
Click OK to save the RADIUS authentication server object.
7.
Load the Juniper Networks dictionary file on the RADIUS server.
8.

Configuring a SecurID Authentication Server

Security devices also support the RSA SecurID system. The device acts as a SecurID
client, forwarding authentication requests to the external server for approval and relaying
Copyright © 2010, Juniper Networks, Inc.

Advertisement

Table of Contents
loading

This manual is also suitable for:

Network and security manager 2010.3

Table of Contents