D-Link DFL-2500 User Guide - Page 161

Realm String

Page 161 highlights

142 Chapter 17. User Authentication Note 1. HTTP authentication will collide with WebUI's remote management service which also uses TCP port 80. To avoid this, please change WebUI port in Advanced Settings for Remote Management before proceeding the authentication configuration, for example, using port 81 instead. 2. In HTTP(s) Agent Options, there are two login types available, HTMLForm and BasicAuth. The problem with BasicAUTH is that Web browsers cache the username and password entered in the 401- Authentication Required dialog. This is normally no problem if the browser is closed down, as it then clears the cache; but for systems with the browser imbedded in the operating system, the cache is harder to clear. Therefore, HTMLForm is recommended. A Realm String can be defined to be shown in the 401- Authentication Required dialog for BasicAUTH option. 3. Timeout can be adjusted in User Authentication → User Authentication Rules → Restrictions. The options are Idle Timeout and Session Timeout. • Idle Timeout: If a user has successfully been authenticated, and no traffic has been seen from his IP address for this number of seconds, he/she will automatically be logged out. The value is 1800 by default. • Session Timeout: If a user has successfully been authenticated, he/she will automatically be logged out after this many seconds, regardless of if the firewall has seen activity from the user or not. • Use timeouts received from the authentication server checkbox: Some RADIUS servers can be configured to return idle-timeout and session values. If this checkbox is selected, the firewall will try to use these timeouts, prior to the timeout values specified above. If no timeouts are received from the authentication server, the timeout values specified above will be used. 4. Another Restrictions configuration is the Multiple Username Logins. Three options are available as explained below: D-Link Firewalls User's Guide

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336
  • 337
  • 338
  • 339
  • 340
  • 341
  • 342
  • 343
  • 344
  • 345
  • 346
  • 347
  • 348
  • 349
  • 350
  • 351
  • 352
  • 353
  • 354
  • 355
  • 356
  • 357
  • 358
  • 359
  • 360
  • 361
  • 362
  • 363
  • 364
  • 365

142
Chapter 17. User Authentication
Note
1. HTTP authentication will collide with WebUI’s remote management
service which also uses TCP port 80. To avoid this, please change
WebUI port in
Advanced Settings
for
Remote Management
before proceeding the authentication configuration, for example, using
port 81 instead.
2. In
HTTP(s) Agent Options
, there are two login types available,
HTMLForm
and
BasicAuth
. The problem with
BasicAUTH
is
that Web browsers cache the username and password entered in the
401- Authentication Required dialog. This is normally no problem if
the browser is closed down, as it then clears the cache; but for
systems with the browser imbedded in the operating system, the
cache is harder to clear. Therefore, HTMLForm is recommended. A
Realm String
can be defined to be shown in the 401- Authentication
Required dialog for BasicAUTH option.
3. Timeout can be adjusted in
User Authentication
User
Authentication Rules
Restrictions
. The options are
Idle
Timeout
and
Session Timeout
.
Idle Timeout:
If a user has successfully been authenticated,
and no traffic has been seen from his IP address for this number
of seconds, he/she will automatically be logged out. The value is
1800 by default.
Session Timeout:
If a user has successfully been authenticated,
he/she will automatically be logged out after this many seconds,
regardless of if the firewall has seen activity from the user or not.
Use timeouts received from the authentication server
checkbox: Some RADIUS servers can be configured to return
idle-timeout and session values. If this checkbox is selected, the
firewall will try to use these timeouts, prior to the timeout values
specified above. If no timeouts are received from the
authentication server, the timeout values specified above will be
used.
4. Another
Restrictions
configuration is the
Multiple Username
Logins
. Three options are available as explained below:
D-Link Firewalls User’s Guide