HP StorageWorks 2/16V HP StorageWorks Fabric OS 5.X Procedures User Guide (AA- - Page 49

Configuring users, Configuring the RADIUS server

Page 49 highlights

Configuring users 1. From the Windows Start menu, select Programs > Administrative Tools > Computer Management to open the Computer Management window. 2. In the Computer Management window, expand the Local Users and Groups folder and select the Groups folder. 3. Right-click the Groups folder and select New Group from the pop-up menu. 4. In the New Group window, provide a Name and Description for the group and click Add. 5. In the Select Users or Groups window, select the user-who should already have been configured-you want to add to the group and click Add. 6. Repeat this for every user you want to add. 7. When you have completed adding all users, click OK. 8. In the New Group window, verify that the users you added in step 4 appear in the Members field and then click Create to create this group. The new groups are created for each login type (admin, switchAdmin, user). Configuring the RADIUS server 1. From the Windows Start menu, select Programs > Administrative Tools > Internet Authentication Service to open the Internet Authentication Service window. 2. In the Internet Authentication Service window, right-click the Clients folder and select New Client from the pop-up menu. NOTE: A client is the device that uses the RADIUS server; in this case, it is the switch. 3. In the Add Client window, provide the following: • Friendly name: The friendly name should be an alias that is easily recognizable as the switch to which you are connecting. • Protocol: Select RADIUS as the protocol. 4. In the Add RADIUS Client window, provide the following: • Client address (IP or DNS): Enter the IP address of the switch. • Client-Vendor: Select RADIUS Standard. • Shared secret: Provide a password. Shared secret is a password used between the client device and server to prevent IP address spoofing by unwanted clients. Keep your shared secret password in a safe place. You must enter this password in the switch configuration. 5. Click Finish and repeat step 2 through step 4 for all switches on which RADIUS authentication is to be used. 6. In the Internet Authentication Service window, right-click the Remote Access Policies folder, and then select New Remote Access Policy from the pop-up window. 7. A remote access policy must be created for each login role (root, admin, factory, switchAdmin, and user) for which you want to use RADIUS, so apply this policy to the user groups that you already created. 8. In the Add Remote Access Policy window, enter an easily identifiable Policy friendly name that enables you to see the switch login for which the policy is being created, and then click Next. 9. After the Add Remote Access Policy window refreshes, click Add. 10.In the Select Attribute window, select Windows Groups and click Add. 11.In the Groups window, click Add. 12.In the Select Groups window, select the user-defined group for which you are creating a policy and click Add. 13.After adding all appropriate groups, click OK. 14.In the Groups window, click OK. Fabric OS 5.x administrator guide 49

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248

Fabric OS 5.x administrator guide
49
Configuring users
1.
From the Windows Start menu, select
Programs > Administrative Tools > Computer Management
to
open the Computer Management window.
2.
In the Computer Management window, expand the
Local Users and Groups
folder and select the
Groups
folder.
3.
Right-click the
Groups
folder and select
New Group
from the pop-up menu.
4.
In the New Group window, provide a Name and Description for the group and click
Add
.
5.
In the Select Users or Groups window, select the user—who should already have been
configured—you want to add to the group and click
Add
.
6.
Repeat this for every user you want to add.
7.
When you have completed adding all users, click
OK
.
8.
In the New Group window, verify that the users you added in
step 4
appear in the Members field and
then click
Create
to create this group.
The new groups are created for each login type (admin, switchAdmin, user).
Configuring the RADIUS server
1.
From the Windows Start menu, select
Programs > Administrative Tools > Internet Authentication
Service
to open the Internet Authentication Service window.
2.
In the Internet Authentication Service window, right-click the
Clients
folder and select
New Client
from
the pop-up menu.
NOTE:
A
client
is the device that uses the RADIUS server; in this case, it is the switch.
3.
In the Add Client window, provide the following:
Friendly name: The friendly name should be an alias that is easily recognizable as the switch to
which you are connecting.
Protocol: Select
RADIUS
as the protocol.
4.
In the Add RADIUS Client window, provide the following:
Client address (IP or DNS)
:
Enter the IP address of the switch.
Client-Vendor: Select
RADIUS Standard
.
Shared secret: Provide a password. Shared secret is a password used between the client device
and server to prevent IP address spoofing by unwanted clients. Keep your shared secret password
in a safe place. You must enter this password in the switch configuration.
5.
Click
Finish
and repeat
step 2
through
step 4
for all switches on which RADIUS authentication is to be
used.
6.
In the Internet Authentication Service window, right-click the
Remote Access Policies
folder, and then
select
New Remote Access Policy
from the pop-up window.
7.
A remote access policy must be created for each login role (root, admin, factory, switchAdmin, and
user) for which you want to use RADIUS, so apply this policy to the user groups that you already
created.
8.
In the Add Remote Access Policy window, enter an easily identifiable
Policy friendly name
that
enables you to see the switch login for which the policy is being created, and then click
Next
.
9.
After the Add Remote Access Policy window refreshes, click
Add
.
10.
In the Select Attribute window, select
Windows Groups
and click
Add
.
11.
In the Groups window, click
Add
.
12.
In the Select Groups window, select the user-defined group for which you are creating a policy and
click
Add
.
13.
After adding all appropriate groups, click
OK
.
14.
In the Groups window, click
OK
.