Configuring Radius Authentication For Login Services - Siemens RUGGEDCOM ROX II User Manual

Cli
Hide thumbs Also See for RUGGEDCOM ROX II:
Table of Contents

Advertisement

Chapter 4
System Administration
Primary and secondary RADIUS servers, typically operating from a common database, can be configured for
redundancy. If the first server does not respond to an authentication request, the request will be forwarded to the
second server until a positive/negate acknowledgment is received.
NOTE
RADIUS authentication activity is logged to the authentication log file var/log/auth.log. Details
of each authentication including the time of occurrence, source and result are included. For more
information about the authentication log file, refer to
RUGGEDCOM ROX II supports RADIUS authentication for the LOGIN and PPP services. Different RADIUS
servers can be configured to authenticate both services separately or in combination.
The LOGIN services consist of the following access types:
• Local console logins via the serial port
• Remote shell logins via SSH and HTTPS
• Secure file transfers using HTTPS, SCP and SFTP (based on SSH)
Authentication requests for LOGIN services will attempt to use RADIUS first and any local authentication settings
will be ignored. Only when there is no response (positive/negative) from any of the configured RADIUS servers
will RUGGEDCOM ROX II authenticate users locally.
The PPP service represents incoming PPP connections via a modem. Authentication requests to the PPP service
use RADIUS only. In the event that no response is received from any configured RADIUS server, RUGGEDCOM
ROX II will not complete the authentication request.
The following sections describe how to configure and manage RADIUS authentication:
Section 4.8.1, "Configuring RADIUS Authentication for LOGIN Services"
Section 4.8.2, "Configuring RADIUS Authentication for PPP Services"
Section 4.8.3, "Configuring RADIUS Authentication for Switched Ethernet Ports"
Section 4.8.1

Configuring RADIUS Authentication for LOGIN Services

To configure RADIUS authentication for LOGIN services, do the following:
IMPORTANT!
Passwords are case-sensitive.
1.
Make sure the CLI is in Configuration mode.
2.
Type the following:
admin authentication radius
Configure the primary or secondary RADIUS server by typing either primary or secondary and
3.
configuring the following parameter(s) as required:
Parameter
address { address }
176
Section 3.9.1, "Viewing
Description
Synopsis: A string 7 to 15 characters long or a string 6 to 40
characters long
The IP address of the server.
Configuring RADIUS Authentication for LOGIN Services
RUGGEDCOM ROX II
CLI User Guide
Logs".

Advertisement

Table of Contents
loading

This manual is also suitable for:

Rx1500Rx1512Rx1501Rx1510Rx1511

Table of Contents