02.10.2013 Views

FTOS Configuration Guide for the C-Series - Force10 Networks

FTOS Configuration Guide for the C-Series - Force10 Networks

FTOS Configuration Guide for the C-Series - Force10 Networks

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

• Privilege level<br />

After gaining authorization <strong>for</strong> <strong>the</strong> first time, you may configure <strong>the</strong>se attributes.<br />

Note: RADIUS au<strong>the</strong>ntication/authorization is done <strong>for</strong> every login. There is no difference<br />

between first-time login and subsequent logins.<br />

Idle Time<br />

Every session line has its own idle-time. If <strong>the</strong> idle-time value is not changed, <strong>the</strong> default value of 30<br />

minutes is used. RADIUS specifies idle-time allow <strong>for</strong> a user during a session be<strong>for</strong>e timeout. When a user<br />

logs in, <strong>the</strong> lower of <strong>the</strong> two idle-time values (configured or default) is used. The idle-time value is updated<br />

if both of <strong>the</strong> following happens:<br />

• The administrator changes <strong>the</strong> idle-time of <strong>the</strong> line on which <strong>the</strong> user has logged in<br />

• The idle-time is lower than <strong>the</strong> RADIUS-returned idle-time<br />

ACL<br />

The RADIUS server can specify an ACL. If an ACL is configured on <strong>the</strong> RADIUS server, and if that ACL<br />

is present, user may be allowed access based on that ACL. If <strong>the</strong> ACL is absent, authorization fails, and a<br />

message is logged indicating <strong>the</strong> this.<br />

RADIUS can specify an ACL <strong>for</strong> <strong>the</strong> user if both of <strong>the</strong> following are true:<br />

• If an ACL is absent<br />

• There is a very long delay <strong>for</strong> an entry, or a denied entry because of an ACL, and a message is logged<br />

Note: The ACL name must be a string. Only standard ACLs in authorization (both RADIUS and TACACS)<br />

are supported. Authorization is denied in cases using Extended ACLs.<br />

Auto-command<br />

You can configure <strong>the</strong> system through <strong>the</strong> RADIUS server to automatically execute a command when you<br />

connect to a specific line. To do this, use <strong>the</strong> command auto-command. The auto-command is executed<br />

when <strong>the</strong> user is au<strong>the</strong>nticated and be<strong>for</strong>e <strong>the</strong> prompt appears to <strong>the</strong> user.<br />

Setting access to privilege levels through RADIUS<br />

Through <strong>the</strong> RADIUS server, you can use <strong>the</strong> command privilege level to configure a privilege level <strong>for</strong><br />

<strong>the</strong> user to enter into when <strong>the</strong>y connect to a session.This value is configured on <strong>the</strong> client system.<br />

146 Security

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!