ZyXEL Communications ZyWALL 1100 User Manual page 525

Zywall/usg series
Hide thumbs Also See for ZyWALL 1100:
Table of Contents

Advertisement

Once an ext-user user has been authenticated, the ZyWALL/USG tries to get the user type (see
Table 209 on page
524) from the external server. If the external server does not have the
information, the ZyWALL/USG sets the user type for this session to User.
For the rest of the user attributes, such as reauthentication time, the ZyWALL/USG checks the
following places, in order.
User account in the remote server.
1
User account (Ext-User) in the ZyWALL/USG.
2
Default user account for AD users (ad-users), LDAP users (ldap-users) or RADIUS users (radius-
3
users) in the ZyWALL/USG.
See
Setting up User Attributes in an External Server on page 535
set up the attributes in an external server.
Ext-Group-User Accounts
Ext-Group-User accounts work are similar to ext-user accounts but allow you to group users by
the value of the group membership attribute configured for the AD or LDAP server. See
33.8.5.1 on page 576
User Groups
User groups may consist of user accounts or other user groups. Use user groups when you want to
create the same rule for several user accounts, instead of creating separate rules for each one.
Note: You cannot put access users and admin users in the same user group.
Note: You cannot put the default admin account into any user group.
The sequence of members in a user group is not important.
User Awareness
By default, users do not have to log into the ZyWALL/USG to use the network services it provides.
The ZyWALL/USG automatically routes packets for everyone. If you want to restrict network
services that certain users can use via the ZyWALL/USG, you can require them to log in to the
ZyWALL/USG first. The ZyWALL/USG is then 'aware' of the user who is logged in and you can create
'user-aware policies' that define what services they can use. See
a user-aware login example.
Finding Out More
• See
Section 33.2.4.3 on page 535
authentication server in order to log in.
• The ZyWALL/USG supports TTLS using PAP so you can use the ZyWALL/USG's local user database
to authenticate users with WPA or WPA2 instead of needing an external RADIUS server.
Chapter 33 Object
for more on the group membership attribute.
for some information on users who use an external
ZyWALL/USG Series User's Guide
525
for a list of attributes and how to
Section
Section 33.2.4.2 on page 534
for

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents