Dell Brocade G620 Brocade 8.0.1 Fabric OS Administratiors Guide - Page 170

In Server Manager, open AD DS tab and then open Active Directory User and Computers.

Page 170 highlights

Managing User Accounts a) In the Internet Authentication Service window, right-click the Remote Access Policies folder, and then select New Remote Access Policy from the pop-up window. A remote access policy must be created for each group of Brocade login permissions (root, admin, switchAdmin, and user) for which you want to use RADIUS. Apply this policy to the user groups that you already created. b) In the Vendor-Specific Attribute Information window, enter the vendor code value 1588 . Click the Yes. It conforms option, and then click Configure Attribute . c) In the Configure VSA (RFC compliant) window, enter the following values, and then click OK . Vendor-assigned attribute number -- Enter the value 1 . Attribute format -- Enter String . Attribute value -- Enter the login role (root, admin, switchAdmin, user, and so on) that the user group must use to log in to the switch. d) After returning to the Internet Authentication Service window, add additional policies for all Brocade login types for which you want to use the RADIUS server. After this is done, you can configure the switch. 7. Add Admin group and CHAP/PAP/PEAP group before adding the user. To add Admin group in Active Directory User and Computers, follow these steps: a) In Server Manager, open AD DS tab and then open Active Directory User and Computers. b) Right-click on the left panel tab and select New > Group from the menu. The New Object - Group dialog box is displayed. c) Enter the Group name as "admin". Select the Group scope as Global and Group type as Security and then click OK. The admin Properties window displayed. d) Enter the Description as "FOS admin role" and click Apply. i 8. Add CHAP group in Active Directory Users and Computers. To add CHAP group, follow these steps: a) In Server Manager, open AD DS tab and then open Active Directory User and Computers. b) Right-click on the left panel tab and select New > Group from the menu. The New Object - Group dialog box is displayed. c) Enter the Group name as "chap". Select the Group scope as Global and Group type as Security and then click OK. The chap Properties window displayed. d) Enter the Description as "FOS chap group" and click Apply. 9. Define a CHAP policy for CHAP group users. To define the CHAP policy, follow these steps: a) Open the Administrative tools > Network policy server > Policies > Network Policies from the menu bar. b) Right-click and select New. The New Network Policy dialog box is displayed. c) Enter the policy name as "swchap". Select the Type of network access server as Unspecified and click Next. d) Click Add and then select the Windows Groups from the list. The Select Group dialog box is displayed. e) Enter the object name to select as "chap" and then click OK. Click Next. The Specify Access Permission window is displayed. f) Select the Access granted option and click Next. The Configure Authentication Methods window is displayed. g) Select the Encrypted authentication (CHAP) check box and click Next. Brocade Fabric OS Administration Guide, 8.0.1 170 53-1004111-02

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336
  • 337
  • 338
  • 339
  • 340
  • 341
  • 342
  • 343
  • 344
  • 345
  • 346
  • 347
  • 348
  • 349
  • 350
  • 351
  • 352
  • 353
  • 354
  • 355
  • 356
  • 357
  • 358
  • 359
  • 360
  • 361
  • 362
  • 363
  • 364
  • 365
  • 366
  • 367
  • 368
  • 369
  • 370
  • 371
  • 372
  • 373
  • 374
  • 375
  • 376
  • 377
  • 378
  • 379
  • 380
  • 381
  • 382
  • 383
  • 384
  • 385
  • 386
  • 387
  • 388
  • 389
  • 390
  • 391
  • 392
  • 393
  • 394
  • 395
  • 396
  • 397
  • 398
  • 399
  • 400
  • 401
  • 402
  • 403
  • 404
  • 405
  • 406
  • 407
  • 408
  • 409
  • 410
  • 411
  • 412
  • 413
  • 414
  • 415
  • 416
  • 417
  • 418
  • 419
  • 420
  • 421
  • 422
  • 423
  • 424
  • 425
  • 426
  • 427
  • 428
  • 429
  • 430
  • 431
  • 432
  • 433
  • 434
  • 435
  • 436
  • 437
  • 438
  • 439
  • 440
  • 441
  • 442
  • 443
  • 444
  • 445
  • 446
  • 447
  • 448
  • 449
  • 450
  • 451
  • 452
  • 453
  • 454
  • 455
  • 456
  • 457
  • 458
  • 459
  • 460
  • 461
  • 462
  • 463
  • 464
  • 465
  • 466
  • 467
  • 468
  • 469
  • 470
  • 471
  • 472
  • 473
  • 474
  • 475
  • 476
  • 477
  • 478
  • 479
  • 480
  • 481
  • 482
  • 483
  • 484
  • 485
  • 486
  • 487
  • 488
  • 489
  • 490
  • 491
  • 492
  • 493
  • 494
  • 495
  • 496
  • 497
  • 498
  • 499
  • 500
  • 501
  • 502
  • 503
  • 504
  • 505
  • 506
  • 507
  • 508
  • 509
  • 510
  • 511
  • 512
  • 513
  • 514
  • 515
  • 516
  • 517
  • 518
  • 519
  • 520
  • 521
  • 522
  • 523
  • 524
  • 525
  • 526
  • 527
  • 528
  • 529
  • 530
  • 531
  • 532
  • 533
  • 534
  • 535
  • 536
  • 537
  • 538
  • 539
  • 540
  • 541
  • 542
  • 543
  • 544
  • 545
  • 546
  • 547
  • 548
  • 549
  • 550
  • 551

a)
In the Internet Authentication Service window, right-click the Remote Access Policies folder, and then select
New Remote
Access Policy
from the pop-up window.
A remote access policy must be created for each group of Brocade login permissions (root, admin, switchAdmin, and user)
for which you want to use RADIUS. Apply this policy to the user groups that you already created.
b)
In the Vendor-Specific Attribute Information window, enter the vendor code value
1588
. Click the
Yes. It conforms
option,
and then click
Configure Attribute
.
c)
In the Configure VSA (RFC compliant) window, enter the following values, and then click
OK
.
Vendor-assigned attribute number -- Enter the value
1
.
Attribute format -- Enter
String
.
Attribute value -- Enter the login role (root, admin, switchAdmin, user, and so on) that the user group must use to log in to
the switch.
d)
After returning to the Internet Authentication Service window, add additional policies for all Brocade login types for which
you want to use the RADIUS server. After this is done, you can configure the switch.
7.
Add Admin group and CHAP/PAP/PEAP group before adding the user.
To add Admin group in Active Directory User and
Computers, follow these steps:
a)
In Server Manager, open AD DS tab and then open Active Directory User and Computers.
b)
Right-click on the left panel tab and select New > Group from the menu.
The New Object - Group dialog box is displayed.
c)
Enter the Group name as "admin". Select the Group scope as Global and Group type as Security and then click OK.
The admin Properties window displayed.
d)
Enter the Description as "FOS admin role" and click Apply.
i
8.
Add CHAP group in Active Directory Users and Computers.
To add CHAP group, follow these steps:
a)
In Server Manager, open AD DS tab and then open Active Directory User and Computers.
b)
Right-click on the left panel tab and select New > Group from the menu.
The New Object - Group dialog box is displayed.
c)
Enter the Group name as "chap". Select the Group scope as Global and Group type as Security and then click OK.
The chap Properties window displayed.
d)
Enter the Description as "FOS chap group" and click Apply.
9.
Define a CHAP policy for CHAP group users.
To define the CHAP policy, follow these steps:
a)
Open the Administrative tools > Network policy server > Policies > Network Policies from the menu bar.
b)
Right-click and select New.
The New Network Policy dialog box is displayed.
c)
Enter the policy name as "swchap". Select the Type of network access server as Unspecified and click Next.
d)
Click Add and then select the Windows Groups from the list.
The Select Group dialog box is displayed.
e)
Enter the object name to select as "chap" and then click OK. Click Next.
The Specify Access Permission window is displayed.
f)
Select the Access granted option and click Next.
The Configure Authentication Methods window is displayed.
g)
Select the Encrypted authentication (CHAP) check box and click Next.
Managing User Accounts
Brocade Fabric OS Administration Guide, 8.0.1
170
53-1004111-02