27.11.2012 Views

IronPort - daily management guide - AsyncOS 7.6.1

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Chapter 8 Common Administrative Tasks<br />

Enabling RADIUS Authentication<br />

OL-25138-01<br />

Working with User Accounts<br />

You can also use a RADIUS directory to authenticate users and assign groups of users to Cisco <strong>IronPort</strong><br />

roles. The RADIUS server should support the CLASS attribute, which <strong>AsyncOS</strong> uses to assign users in<br />

the RADIUS directory to Cisco <strong>IronPort</strong> user roles. <strong>AsyncOS</strong> supports two authentication protocols for<br />

communicating with the RADIUS server: Password Authentication Protocol (PAP) and Challenge<br />

Handshake Authentication Protocol (CHAP).<br />

To assign RADIUS users to Cisco <strong>IronPort</strong> user roles, first set the CLASS attribute on the RADIUS<br />

server with a string value of , which will be mapped to Cisco <strong>IronPort</strong> user roles. The<br />

CLASS attribute may contain letters, numbers, and a dash, but cannot start with a dash. <strong>AsyncOS</strong> does<br />

not support multiple values in the CLASS attribute. RADIUS users belonging to a group without a<br />

CLASS attribute or an unmapped CLASS attribute cannot log into the appliance.<br />

If the appliance cannot communicate with the RADIUS server, the user can log in with a local user<br />

account on the appliance.<br />

Note If an external user changes the user role for their RADIUS group, the user should log out of the appliance<br />

and then log back in. The user will have the permissions of their new role.<br />

To enable external authentication using RADIUS:<br />

Step 1 On the System Administration > Users page, click Enable. The Edit External Authentication page is<br />

displayed.<br />

Step 2 Select the Enable External Authentication check box.<br />

Step 3 Select RADIUS for the authentication type.<br />

Figure 8-18 Enabling External Authentication Using RADIUS<br />

Step 4 Enter the host name for the RADIUS server.<br />

Step 5 Enter the port number for the RADIUS server. The default port number is 1812.<br />

Step 6 Enter the Shared Secret password for the RADIUS server.<br />

Note When enabling external authentication for a cluster of Cisco <strong>IronPort</strong> appliances, enter the same<br />

Shared Secret password on all appliances in the cluster.<br />

Step 7 Enter the number of seconds that the appliance waits for a response from the server before timing out.<br />

Cisco <strong>IronPort</strong> <strong>AsyncOS</strong> 7.6 for Email Daily Management Guide<br />

8-25

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!