Configuring An Ldap Authentication Server; Configuring A Tacacs Authentication Server - Juniper NETWORK AND SECURITY MANAGER 2010.3 - ADMINISTRATION GUIDE REV1 Administration Manual

Table of Contents

Advertisement

Network and Security Manager Administration Guide
398
A SecurID ACE server can store L2TP, XAuth, and device administrator user accounts for
authentication purposes; but it cannot assign L2TP, XAuth remote settings, or device
administrator privileges.

Configuring an LDAP Authentication Server

Lightweight Directory Access Protocol (LDAP) a protocol for organizing and accessing
information in a hierarchical structure resembling a branching tree. LDAP is used to locate
resources, such as organizations, individuals, and files on a network, and helps
authenticate users attempting to connect to networks controlled by directory servers.
To create an LDAP authentication server object, configure the following:
LDAP Server Port: The port number on the LDAP server to which the security device
sends authentication requests. The default port number is 389.
Common Name Identifier: The identifier used by the LDAP server to identify the
individual entered in a LDAP server. For example, an entry of "uid" means " user ID" and
"cn" for " common name."
Distinguished Name (dn): The path used by the LDAP server before using the common
name identifier to search for a specific entry. (For example, c=us;o=juniper, where "c"
stands for "country," and "o" for "organization.")
Supported Users
An LDAP server supports the following types of users and authentication features:
Auth users
L2TP users (user authentication; L2TP user receives default L2TP settings from the
security device)
XAuth users (user authentication; no support for remote setting assignments)
Admin users (user authentication; administrator user receives default privilege
assignment of read-only)
LDAP servers cannot assign L2TP or XAuth remote settings.

Configuring a TACACS Authentication Server

Terminal Access Controller Access Control System (TACACS) is a security application.
As of Release 2007.3, you can configure TACACS to authenticate administrator users.
To configure the TACACS server:
In the NSM main navigation tree, click Object Manager > Authentication Servers.
1.
Select the TACACS server type from the Authentication Server dialog box.
2.
Configure the following parameters and click OK.
3.
Copyright © 2010, Juniper Networks, Inc.

Advertisement

Table of Contents
loading

This manual is also suitable for:

Network and security manager 2010.3

Table of Contents