11.07.2015 Views

PDF user manual for CopperEdge 150

PDF user manual for CopperEdge 150

PDF user manual for CopperEdge 150

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

3. The Radius Reply-Message attribute may also containa second 128-character (maximum) text string <strong>for</strong> useif you want the server to ask the <strong>user</strong> <strong>for</strong> additionalin<strong>for</strong>mation or to repeat the previous login attempt.The <strong>CopperEdge</strong> Radius client will respond to oneAccess_Challenge by resending the same UserNameand Password. If the server does not accept it, the loginfails. The string goes with the Access_Challenge packet.It appears in the <strong>CopperEdge</strong> Event Log.4. Finally, the Radius server must use the same sharedsecret (AuthKey) string when configuring the bothPrimary and Secondary SCM clients. We recommendthat you use the same AuthKey system-wide, but like agood password, it should be short-lived, unpredictable,and changed at irregular intervals.&RQILJXULQJ&RSSHU(GJHIRU5DGLXV6HUYHUVWhen the Radius server is configured and ready to communicate,and its database has been provisioned with the <strong>user</strong> database, the <strong>CopperEdge</strong> cmRadius MIB group can be configured:1. With cmRadius in its default state (Authentication=Disabled), configure all of its objects exceptauthentication. Example:CRAFT> set cmradius authkey=4cr37eiauthprimaryipaddr=10.122.4.4 authprimaryport=1645acctprimaryipaddr=10.122.4.6 acctprimaryport=1646Be sure to use whichever port numbers are recognizedby your Radius servers. Although the officially assignedport numbers <strong>for</strong> Radius Authentication andAccounting are 1812 and 1813, respectively, manycurrent radius servers still use the port numbers of theoriginal RFC: 1645 <strong>for</strong> authentication, and 1646 <strong>for</strong>accounting. Be sure that the numbers you assign inthe <strong>CopperEdge</strong> cmRadius configuration match thoseused by your remote Radius servers.2. When you are sure the rest of the configuration iscomplete and correct, activate the Radius capability:CRAFT> set cmradius authentication=enabledFor more data about the cmRadius MIB group, see the Copper-Edge <strong>150</strong> CopperCraft Reference and MIB Definitions <strong>manual</strong>.&KDSWHU$GYDQFHG&RQILJXUDWLRQ

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!