U
S
NIVERSAL
UBSCRIBER
If you want to enable RADIUS, click on the check box for
2.
Authentication
If you enabled the RADIUS interface, you must provide additional information
that is directly related to the RADIUS functionality. The system requires
parameters for the following categories:
Authentication
! ! ! !
authentication and automatic subscriber reauthentication, and requires
you to define IP addresses, ports, and secret keys for the primary and
secondary RADIUS servers (the secondary server is optional).
Accounting
! ! ! !
accounting service, and also requires the necessary IP addresses, ports
and secret keys for the primary and secondary RADIUS accounting
servers. The RADIUS accounting server is responsible for receiving
accounting requests and returning a response to the client indicating that
it has received the request.
Retransmission Options
! ! ! !
data retransmission method (failover or round-robin), the retransmission
frequency, and how many retransmissions the system should attempt.
ISP Account Creation
! ! ! !
parameters, including the URLs for the ISP portal Web page and the
account creation Web page, and the ISP server IP address.
Miscellaneous Options
! ! ! !
parameter and information related to a Network Access Server (NAS).
With the RADIUS client/server model, the NAS functions as a client of
the RADIUS accounting server. The NAS is responsible for passing
user accounting information to the accounting server.
Authentication
If you enabled RADIUS authentication, click on the check box for
3.
Automatic Subscriber Reauthentication
When "Enable Automatic Subscriber Reauthentication" is enabled, each time a
subscriber is successfully authenticated via RADIUS they are added to a special
file on the USG (not the standard authorization file). If an entry in the USG's
memory table is deleted, instead of prompting the affected subscriber for their
user name and password, the USG looks up the special file and sends a request to
the RADIUS server with the subscriber's user name and password stored in the
file (without prompting the subscriber). See note.
"
Because usernames/passwords are stored as text on the USG, use the
USG's "Access Control" feature
you cannot guarantee security on the USG.
System Administration
G
™
ATEWAY
.
– This category requires input for enabling RADIUS
– This category requires input for enabling the RADIUS
– This category requires you to define the
– This category defines the ISP account
– This category requires an idle timeout
Enable RADIUS
.
(page
63) or disable this function if
Enable
91
Need help?
Do you have a question about the Universal subscriber gateway and is the answer not in the manual?