11.07.2015 Views

PDF user manual for CopperEdge 150

PDF user manual for CopperEdge 150

PDF user manual for CopperEdge 150

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

1 2 7 (Once the Radius server is provisioned and cmRadiusAuth is enabled,security features are under control of the Radius server. You can stillconfigure the CopperCraft cmOperatorTable, but its contents will nolonger be used. Operators configured in cmOperator and notcontained in the Radius server database will not be able to log in. TheRadius protocol requires that operator names and passwords are fullycase-sensitive.To make a request <strong>for</strong> authentication, the <strong>CopperEdge</strong> sends anAccess-Request packet with the following data to the server:Access-Request Packet DataAttribute Value NoteUser-Name Text string input by <strong>user</strong> Maximum of 32 characters.User-Password Text string input by <strong>user</strong> Maximum of 32 characters. This field is one-wayhashed using the MD5 algorithm.Note: The CE does not send passwords <strong>for</strong>SNMP operators (such as Public and Private) inauthentication requests.NAS-IP-Address CE-IP-Address This is the IP-Address of Ethernet port 1.2.1 or1.15.1, depending on which SCM is beingaccessed by the operator. This field will contain0.0.0.0 if there is no IP address configured <strong>for</strong>that port CE Management Ethernet IP address.NAS-Identifier CE-System-Name This attribute is omitted if CE-System-Name is anempty string.Upon receiving of the request by <strong>CopperEdge</strong>, the Radius servermay respond with an Access_Accept packet with the followingdata in it:Access-Accept Packet DataAttribute Value NoteIdle-TimeoutFilter-IdFilter-IdIdle Timeout value in second(0 to 2147483647)“Context = HH”Note: Be sure to enter thisexactly as shown, with aspace be<strong>for</strong>e and after theequal sign.“Privilege = DD”Note: Be sure to enter thisexactly as shown, with aspace be<strong>for</strong>e and after theequal sign.If this field is empty, the CE uses a predefinedsystem Idle Timeout of 15 minutes.Where HH is a Hex number of the login context<strong>for</strong> this operator. Possible context is a bit map: 01= CONTEXT_HTTP; 02 = CONTEXT_SNMP; 04= CONTEXT_TELNET; 08 = CONTEXT_SERIAL;10 = CONTEXT_SYSTEM; 20 =CONTEXT_FTP; 40 = CONTEXT_SHELLWhere DD is a decimal number specified level ofprivilege designated to the particular operator. Anumber represents level of privilege: 1 = VIEW; 2= MONITOR; 3 = PROVISION; 4 = SECURITY&KDSWHU$GYDQFHG&RQILJXUDWLRQ

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!