Dell EqualLogic PS6210XS EqualLogic Group Manager Administrator s Guide PS Ser - Page 61

Admin-Repl-Site-Access, VSA vendor ID

Page 61 highlights

• You plan to select the Require vendor-specific RADIUS attribute option when you configure the group to use a RADIUS authentication server. You must specify the EQL-Admin-Privilege attribute. Table 16. Vendor-Specific Attributes describes the Dell vendor-specific attributes and values for RADIUS attributes. Table 16. Vendor-Specific Attributes Attribute Field EQL-Admin-Privilege VSA vendor ID Specifies that the account is a group administrator account or a VSA number pool administrator account. VSA syntax The RADIUS server must return the value of this attribute to the group in the Access-Accept message. Required Value 12740 6 Decimal (0 for group administrator; 1 for pool administrator; 2 for pool administrator with read access to the entire group; 3 for volume administrator). To create a read-only account, set the EQL-Admin-Privilege attribute to 0 and the AdminAccount-Type attribute to RO. Admin-Pool-Access Specifies the pools to which the pool administrator account has access and, for volume administrators, the account's storage within that pool. VSA vendor ID VSA number VSA syntax Required if the value of the EQL-Admin-Privilege attribute is 1 (pool administrator account) or 3 (volume administrator account). The quota for volume administration accounts is expressed as PoolNameQuota, with gb and mb (representing GB and MB, respectively) appended to the quota. For example: Pool1 25gb sets the quota for Pool1 to 25GB, and Pool1 500mb sets a quota of 500MB. Use unlimited to set an unlimited quota for the pool (for example, Pool1 unlimited). If no unit is specified, the default capacity unit is MB. 12740 7 String (comma-separated list of pools; 3 to 247 ASCII characters) Admin-Repl-Site-Access Specifies the sites to which the volume administrator can replicate volumes. Required if the value of the EQL-AdminPrivilege attribute is 3 (volume administrator account). Used only for volume administrators. VSA vendor ID VSA number VSA syntax NOTE: A replication quota must be included inside the Admin-Repl-Site-Access attribute for authentication to work properly. Admin-Account-Type Specifies whether the account is read-only (RO) or read-write (RW). VSA vendor ID VSA number VSA syntax 12740 8 String (comma-separated list of sites; 3 to 249 ASCII characters) 12740 9 RO or RW Admin-Full-Name (Optional) Name of the administrator using the account. VSA vendor ID VSA number 12740 1 About Group-Level Security 61

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336
  • 337
  • 338
  • 339
  • 340
  • 341
  • 342
  • 343
  • 344
  • 345
  • 346
  • 347
  • 348
  • 349
  • 350
  • 351
  • 352
  • 353
  • 354
  • 355

You plan to select the
Require vendor-specific RADIUS attribute
option when you
configure
the group to use a
RADIUS authentication server. You must specify the
EQL-Admin-Privilege
attribute.
Table 16.
Vendor-Specific
Attributes
describes the Dell
vendor-specific
attributes and values for RADIUS attributes.
Table 16.
Vendor-Specific
Attributes
Attribute
Field
Required Value
EQL-Admin-Privilege
Specifies
that the account is a group administrator account or a
pool administrator account.
The RADIUS server must return the value of this attribute to the
group in the Access-Accept message.
VSA vendor ID
VSA number
VSA syntax
12740
6
Decimal (
0
for group administrator;
1
for pool administrator;
2
for pool
administrator with read access to the
entire group;
3
for volume
administrator).
To create a read-only account, set
the
EQL-Admin-Privilege
attribute to
0
and the
Admin-
Account-Type
attribute to
RO
.
Admin-Pool-Access
Specifies
the pools to which the pool administrator account has
access and, for volume administrators, the account’s storage
within that pool.
Required if the value of the
EQL-Admin-Privilege
attribute
is
1
(pool administrator account) or
3
(volume administrator
account).
The quota for volume administration accounts is expressed as
PoolNameQuota
, with gb and mb (representing GB and MB,
respectively) appended to the quota.
For example:
Pool1 25gb
sets the quota for Pool1 to 25GB,
and
Pool1 500mb
sets a quota of 500MB. Use
unlimited
to set an unlimited quota for the pool (for example,
Pool1
unlimited
). If no unit is
specified,
the default capacity unit is
MB.
VSA vendor ID
VSA number
VSA syntax
12740
7
String (comma-separated list of
pools; 3 to 247 ASCII characters)
Admin-Repl-Site-Access
Specifies
the sites to which the volume administrator can
replicate volumes. Required if the value of the
EQL-Admin-
Privilege
attribute is 3 (volume administrator account).
Used only for volume administrators.
NOTE: A replication quota must be included inside the
Admin-Repl-Site-Access
attribute for
authentication to work properly.
VSA vendor ID
VSA number
VSA syntax
12740
8
String (comma-separated list of sites;
3 to 249 ASCII characters)
Admin-Account-Type
Specifies
whether the account is read-only (
RO
) or read-write
(
RW
).
VSA vendor ID
VSA number
VSA syntax
12740
9
RO or RW
Admin-Full-Name
(Optional) Name of the administrator using the account.
VSA vendor ID
VSA number
12740
1
About Group-Level Security
61