Extreme Networks Summit WM3000 Series Manual de usuario Pagina 27

  • Descarga
  • Añadir a mis manuales
  • Imprimir
  • Pagina
    / 72
  • Tabla de contenidos
  • MARCADORES
  • Valorado. / 5. Basado en revisión del cliente
Vista de pagina 26
Author: Chad Smith
WM 3000 Series Wireless Controller (v5.1)
Implementation Guide –
RADIUS Authentication
Effective Date: 07/05/2011
Page 27 of 72
© 2011 Extreme Networks, Inc. All rights reserved.
6.5 RADIUS Network Policies
When the RADIUS server receives a connection request, the Network Policy is used to
authenticate the user. If approved for access, the policy dictates various characteristics or
roles the client should receive. These directives are passed on through the use of VSAs or
Vendor Specific Attributes.
In this scenario, two policies are defined for the users. The first applies to administrative
users. These users will have access to the WM by all methods available (SSH, Web,
console) and will be allowed to perform configuration changes (super user access). The
second policy will allow members of the domain users group (non-administrators) to access
the WM’s web interface and view the statistics and configuration.
The Extreme VSAs for the WM controller are as follows:
VSA Name
Attribute
Number
Type
Values
Extreme-Service-Type
1
Integer(Decimal)
Monitor Role: Value is 1. (read-only access to the controller)
Helpdesk Role: Value is 2. (helpdesk/support access to the
controller)
Nwadmin Role: Value is 4. (all wired and wireless access to the
controller)
Sysadmin Role: Value is 8. (System administrator access)
WebAdmin Role: Value is 16. (Guest user application access)
Superuser Role: Value is 32768. (grants full read/write access to
the controller)
NOTE: To configure multiple roles this value may be
configured multiple times with different values for each role.
Extreme-Login-Service
100
Integer(Decimal)
# Console Access: Value is 128. (user is allowed to login only from
console)
# Telnet Access: Value is 64. (use is allowed to login only from
telnet session)
# SSH Access: Value is 32. (user is allowed to login only from ssh
session)
# Web Access: Value is 16. (user is allowed to login only from
web/applet)
NOTE: To configure multiple access methods this value can be
set multiple times with different access values, or the desired
values can be added together and entered as a single value.
Vista de pagina 26
1 2 ... 22 23 24 25 26 27 28 29 30 31 32 ... 71 72

Comentarios a estos manuales

Sin comentarios