Dell EqualLogic PS6210XS EqualLogic Group Manager Administrator s Guide PS Ser - Page 53

About Group-Level Security, Enable or Disable GUI and CLI Access

Page 53 highlights

6 About Group-Level Security Group Manager supports several strategies to ensure that only the people and applications that have approved credentials can log in to the PS Series group and gain access to your data. Security can be accomplished through the following methods: • Administration accounts - You can assign several predefined levels of administrative accounts to provide individuals with various levels of access to Group Manager's features. To log in to the group, you must have a valid group administration account. Different account types provide different privileges. The default account, grpadmin, provides all privileges. • RADIUS authentication - You can control access to a group and its volumes by using administration accounts to log in to the group. Use a RADIUS authentication server to enable you to centralize account management. • Active Directory/LDAP - You can authenticate administrator sessions using LDAP. You can give group, pool, or volume administrator privileges to individual Active Directory users or to entire Active Directory groups. • SNMP - Simple Network Management Protocol (SNMP) enables read-only access to the group. SAN Headquarters (SAN HQ) uses SNMP to retrieve data from a group. • VDS/VSS access control - Enables Windows VDS and VSS access to the group. You must create at least one VDS/VSS access control policy that matches the access control credentials you configure on the computer by using Remote Setup Wizard or Auto-Snapshot Manager/Microsoft Edition. To control access to data at the volume level, you can enable authentication at the iSCSI level. Enable or Disable GUI and CLI Access 1. Click Group → Group Configuration. 2. Click the Administration tab to open the Access panel. 3. Enable or disable the GUI or CLI access options and network services. 4. Click the Save All Changes icon in the upper-right corner of the Group Configuration window. NOTE: The CLI provides detailed control over the group's use of cryptographic protocols. For more information, see the grpparams crypto-legacy-protocols command in the Dell EqualLogic Group Manager CLI Reference Guide. Switch Administration Authentication Type To switch the authentication type for the group: 1. Click Group → Group Configuration. 2. Click the Administration tab. 3. In the Authentication panel, select either: • Local only - Uses local authentication and local administrator users only. • Active Directory - Uses LDAP authentication, users, and groups in addition to local authentication and administrator accounts. When this option is selected, the LDAP settings button is available. • RADIUS- Uses RADIUS authentication and users in addition to local authentication and administrator accounts. About Administration Accounts Administration accounts provide various levels of access to Group Manager's features. You must have a valid group administration account in order to log into Group Manager and gain access to a group. About Group-Level Security 53

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336
  • 337
  • 338
  • 339
  • 340
  • 341
  • 342
  • 343
  • 344
  • 345
  • 346
  • 347
  • 348
  • 349
  • 350
  • 351
  • 352
  • 353
  • 354
  • 355

6
About Group-Level Security
Group Manager supports several strategies to ensure that only the people and applications that have approved credentials can log in
to the PS Series group and gain access to your data. Security can be accomplished through the following methods:
Administration accounts — You can assign several
predefined
levels of administrative accounts to provide individuals with various
levels of access to Group Manager’s features. To log in to the group, you must have a valid group administration account.
Different
account types provide
different
privileges. The default account, grpadmin, provides all privileges.
RADIUS authentication — You can control access to a group and its volumes by using administration accounts to log in to the
group. Use a RADIUS authentication server to enable you to centralize account management.
Active Directory/LDAP — You can authenticate administrator sessions using LDAP. You can give group, pool, or volume
administrator privileges to individual Active Directory users or to entire Active Directory groups.
SNMP — Simple Network Management Protocol (SNMP) enables read-only access to the group. SAN Headquarters (SAN HQ)
uses SNMP to retrieve data from a group.
VDS/VSS access control — Enables Windows VDS and VSS access to the group. You must create at least one VDS/VSS
access control policy that matches the access control credentials you
configure
on the computer by using Remote Setup Wizard
or Auto-Snapshot Manager/Microsoft Edition.
To control access to data at the volume level, you can enable authentication at the iSCSI level.
Enable or Disable GUI and CLI Access
1.
Click
Group
Group
Configuration
.
2.
Click the
Administration
tab to open the Access panel.
3.
Enable or disable the GUI or CLI access options and network services.
4.
Click the Save All Changes icon in the upper-right corner of the Group
Configuration
window.
NOTE: The CLI provides detailed control over the group’s use of cryptographic protocols. For more information, see the
grpparams crypto-legacy-protocols command in the
Dell EqualLogic Group Manager CLI Reference Guide
.
Switch Administration Authentication Type
To switch the authentication type for the group:
1.
Click
Group
Group
Configuration
.
2.
Click the
Administration
tab.
3.
In the Authentication panel, select either:
Local only
— Uses local authentication and local administrator users only.
Active Directory
— Uses LDAP authentication, users, and groups in addition to local authentication and administrator
accounts. When this option is selected, the
LDAP settings
button is available.
RADIUS
— Uses RADIUS authentication and users in addition to local authentication and administrator accounts.
About Administration Accounts
Administration accounts provide various levels of access to Group Manager’s features. You must have a valid group administration
account in order to log into Group Manager and gain access to a group.
About Group-Level Security
53