Authentication Using Radius - Alaxala AX2200S Series Configuration Manual

Table of Contents

Advertisement

8 Login Security and RADIUS
Table 8-4 Description of supported RADIUS attributes
Attribute name
User-Name
User-Password
Service-Type
NAS-IP-Address
Reply-Message
State
NAS-Identifier
#1
Access-Accept and Access-Reject ignore Reply-Message.
#2
For details on one-time password authentication, see 14 One-time Password
Authentication [OP-OTP] in the Configuration Guide Vol. 2.

8.2.3 Authentication using RADIUS

This subsection describes RADIUS authentication used for login authentication.
Selecting a RADIUS server and automatic-restoration functionality, which is described later,
can be used in the same way in Layer 2 authentication. For details, see 5 Overview of
Layer 2 Authentication in the Configuration Guide Vol. 2.
(1) Selecting login authentication services
You can specify multiple services for login authentication. The specifiable services are
RADIUS authentication (general-use RADIUS server authentication or RADIUS server
group authentication) and local password authentication (the Switch's own authentication
function implemented by the
The following figure shows a correlation diagram of authentication method settings.
88
Attrib
Packet types
ute
value
1
Access-Request
2
Access-Request
6
Access-Request
4
Access-Request
18
Access-Challenge
Access-Accept
Access-Reject
24
Access-Challenge
Access-Request
32
Access-Request
password
Description
The name of the user being authenticated.
The password of the user being
authenticated, sent in encrypted form
Login (value = 1), Ignored when attached to
Access-Accept or Access-Reject.
The IP address of the Switch. From among
the VLAN interfaces that have an IP
address registered, the IP address of the
smallest VLAN ID is used.
Text character string.
#1
This attribute value is displayed as a
#1
message in the telnet page displayed during
one-time password authentication
Text character string.
The Switch retains the State information
passed by Access-Challenge used in
one-time password authentication#2.
When performing Access-Request for
Access-Challenge, the State information
retained on the Switch is added.
The device name of the Switch. This is not
attached if a device name was not set.
command).
#2
.

Advertisement

Table of Contents
loading

This manual is also suitable for:

Ax1250s seriesAx1240s series

Table of Contents