McAfee MAP-3300-SWG Product Guide - Page 245

Role Mappings RADIUS, Test RADIUS, Table 243, Option definitions

Page 245 highlights

Overview of System features Users, Groups and Services Role Mappings (RADIUS) Table 243 Option definitions Option Definition Use locally defined user details to determine an authenticated user's role The user's role will be determined by a locally-defined user (of type External user) Use data returned from The user's role will be determined by the attributes returned by the RADIUS the server to determine an server. authenticated user's role You can add role mappings by selecting Add Mapping. This provides the following options: Attribute Name - specifies the attribute name returned from the RADIUS server to be checked. For example, Service-Type Attribute value - specifies the attribute value returned from the RADIUS server to be checked. For example, Administrative-User. (The specific attribute name and values used will be defined by the RADIUS server you are connecting to. Please contact the RADIUS server administrator if you are unsure which values to use.) Role - choose the role that you wish to assign to a user who has these attributes. Default Role Choose the role to assign to a user who does not match any of the criteria above. None indicates that no role will be assigned, meaning that login will be refused unless a role is defined by a local user of type External user or a RADIUS attribute. Role Mappings (Kerberos) Table 244 Option definitions Option Definition Default Role Choose the role to assign to a user who does not match any of the criteria above. None indicates that no role will be assigned, meaning that login will be refused unless a role is defined by a local user of type External user. Test (RADIUS) This dialog box allows you to test that the connection to your RADIUS server is working. Table 245 Option definitions Option Definition Username Enter a RADIUS user name to authenticate as (include the realm and delimiter character, if required). Password Enter the password for the RADIUS user that you entered in the Username box. Test Click Test to authenticate against the RADIUS server. If the request is successful, a green check mark and Authentication test succeeded is displayed. You will also see the Access-Accept response sent back from the RADIUS server in the Output box and any attributes returned. If the request fails, a warning icon and the message Authentication test failed is displayed. The Access-Reject or other message is returned from the RADIUS server in the Output field. McAfee Email and Web Security Appliances 5.6.0 Product Guide 245

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336

Role Mappings (RADIUS)
Table 243
Option definitions
Option
Definition
Use locally defined user
details to determine an
authenticated user's role
The user's role will be determined by a locally-defined user (of type
External user
)
Use data returned from
the server to determine an
authenticated user's role
The user's role will be determined by the attributes returned by the RADIUS
server.
You can add role mappings by selecting
Add Mapping
. This provides the following
options:
Attribute Name
- specifies the attribute name returned from the RADIUS server to
be checked. For example,
Service-Type
Attribute value
- specifies the attribute value returned from the RADIUS server to
be checked. For example,
Administrative-User
. (The specific attribute name
and values used will be defined by the RADIUS server you are connecting to.
Please contact the RADIUS server administrator if you are unsure which values
to use.)
Role
- choose the role that you wish to assign to a user who has these attributes.
Default Role
Choose the role to assign to a user who does not match any of the criteria above.
None
indicates that no role will be assigned, meaning that login will be refused
unless a role is defined by a local user of type
External user
or a RADIUS attribute.
Role Mappings (Kerberos)
Table 244
Option definitions
Option
Definition
Default Role
Choose the role to assign to a user who does not match any of the criteria above.
None
indicates that no role will be assigned, meaning that login will be refused unless a
role is defined by a local user of type
External user
.
Test (RADIUS)
This dialog box allows you to test that the connection to your RADIUS server is working.
Table 245
Option definitions
Option
Definition
Username
Enter a RADIUS user name to authenticate as (include the realm and delimiter character, if
required).
Password
Enter the password for the RADIUS user that you entered in the
Username
box.
Test
Click
Test
to authenticate against the RADIUS server.
If the request is successful, a green check mark and
Authentication test succeeded
is displayed.
You will also see the Access-Accept response sent back from the RADIUS server in the
Output
box and any attributes returned.
If the request fails, a warning icon and the message
Authentication test failed
is displayed. The
Access-Reject or other message is returned from the RADIUS server in the
Output
field.
Overview of System features
Users, Groups and Services
McAfee Email and Web Security Appliances 5.6.0 Product Guide
245