Dell PowerConnect W Clearpass 100 Software 3.7 Deployment Guide - Page 412

Security Configuration

Page 412 highlights

Security Configuration Table 48 Security Configuration Settings Value Description security.max_attributes = 200 The maximum number of attributes permitted in a RADIUS packet. Packets which have more than this number of attributes in them will be dropped. If this number is set too low, then no RADIUS packets will be accepted. If this number is set too high, then an attacker may be able to send a small number of packets which will cause the server to use all available memory on the machine. Setting this number to 0 means "allow any number of attributes". security.reject_delay = 1 When sending an Access-Reject, it can be delayed for a few seconds. This may help slow down a DoS attack. It also helps to slow down people trying to bruteforce crack a user's password. Setting this number to 0 means "send rejects immediately". If this number is set higher than 'cleanup_delay', then the rejects will be sent at 'cleanup_delay' time, when the request is deleted from the internal cache of requests. The range of useful values are 1 to 5. security.status_server = no Sets whether or not the server will respond to Status-Server requests. When sent a Status-Server message, the server responds with an Access-Accept packet, containing a Reply-Message attribute, which is a string describing how long the server has been running. Allowed values are no and yes. Proxy Configuration Table 49 Proxy Configuration Settings Value Description proxy_requests = yes Turns proxying of RADIUS requests on or off. The server has proxying turned on by default. If your system is not set up to proxy requests to another server, then you can turn proxying off here. This will save a small amount of resources on the server. If you have proxying turned off, and your configuration files say to proxy a request, then an error message will be logged. Allowed values: no, yes proxy.synchronous = no If the NAS re-sends the request to us, we can immediately re-send the proxy request to the end server. To do so, use 'yes' here. If this is set to 'no', then we send the retries on our own schedule, and ignore any duplicate NAS requests. If you want to have the server send proxy retries ONLY when the NAS sends its retries to the server, then set this to 'yes', and set the other proxy configuration parameters to 0 (zero). Additionally, if you want 'failover' to work, the server must manage retries and timeouts. Therefore, if this is set to yes, then no failover functionality is possible. Allowed values: no, yes proxy.retry_delay = 5 The time (in seconds) to wait for a response from the proxy, before re-sending the proxied request. If this time is set too high, then the NAS may re-send the request, or it may give up entirely, and reject the user. If it is set too low, then the RADIUS server which receives the proxy request will get kicked unnecessarily. proxy.retry_count = 3 The number of retries to send before giving up, and sending a reject message to the NAS. 412 | Reference Amigopod 3.7 | Deployment Guide

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336
  • 337
  • 338
  • 339
  • 340
  • 341
  • 342
  • 343
  • 344
  • 345
  • 346
  • 347
  • 348
  • 349
  • 350
  • 351
  • 352
  • 353
  • 354
  • 355
  • 356
  • 357
  • 358
  • 359
  • 360
  • 361
  • 362
  • 363
  • 364
  • 365
  • 366
  • 367
  • 368
  • 369
  • 370
  • 371
  • 372
  • 373
  • 374
  • 375
  • 376
  • 377
  • 378
  • 379
  • 380
  • 381
  • 382
  • 383
  • 384
  • 385
  • 386
  • 387
  • 388
  • 389
  • 390
  • 391
  • 392
  • 393
  • 394
  • 395
  • 396
  • 397
  • 398
  • 399
  • 400
  • 401
  • 402
  • 403
  • 404
  • 405
  • 406
  • 407
  • 408
  • 409
  • 410
  • 411
  • 412
  • 413
  • 414
  • 415
  • 416
  • 417
  • 418
  • 419
  • 420
  • 421
  • 422
  • 423
  • 424
  • 425
  • 426
  • 427
  • 428
  • 429
  • 430
  • 431
  • 432
  • 433
  • 434
  • 435
  • 436
  • 437
  • 438

412
| Reference
Amigopod 3.7
|
Deployment Guide
Security Configuration
Proxy Configuration
Table 48
Security Configuration Settings
Value
Description
security.max_attributes
= 200
The maximum number of attributes permitted in a RADIUS packet. Packets which
have more than this number of attributes in them will be dropped. If this number
is set too low, then no RADIUS packets will be accepted. If this number is set too
high, then an attacker may be able to send a small number of packets which will
cause the server to use all available memory on the machine. Setting this number
to 0 means “allow any number of attributes”.
security.reject_delay
= 1
When sending an Access-Reject, it can be delayed for a few seconds. This may
help slow down a DoS attack. It also helps to slow down people trying to brute-
force crack a user’s password.
Setting this number to 0 means “send rejects immediately”. If this number is set
higher than ‘cleanup_delay’, then the rejects will be sent at ‘cleanup_delay’ time,
when the request is deleted from the internal cache of requests. The range of
useful values are 1 to 5.
security.status_server
= no
Sets whether or not the server will respond to Status-Server requests. When sent
a Status-Server message, the server responds with an Access-Accept packet,
containing a Reply-Message attribute, which is a string describing how long the
server has been running. Allowed values are
no
and
yes
.
Table 49
Proxy Configuration Settings
Value
Description
proxy_requests
= yes
Turns proxying of RADIUS requests on or off. The server has proxying turned on by
default. If your system is not set up to proxy requests to another server, then you can
turn proxying off here. This will save a small amount of resources on the server. If you
have proxying turned off, and your configuration files say to proxy a request, then an
error message will be logged. Allowed values: no, yes
proxy.synchronous
= no
If the NAS re-sends the request to us, we can immediately re-send the proxy request
to the end server. To do so, use ‘yes’ here. If this is set to ‘no’, then we send the retries
on our own schedule, and ignore any duplicate NAS requests. If you want to have the
server send proxy retries ONLY when the NAS sends its retries to the server, then set
this to ‘yes’, and set the other proxy configuration parameters to 0 (zero).
Additionally, if you want ‘failover’ to work, the server must manage retries and
timeouts. Therefore, if this is set to yes, then no failover functionality is possible.
Allowed values: no, yes
proxy.retry_delay
= 5
The time (in seconds) to wait for a response from the proxy, before re-sending the
proxied request. If this time is set too high, then the NAS may re-send the request, or it
may give up entirely, and reject the user. If it is set too low, then the RADIUS server
which receives the proxy request will get kicked unnecessarily.
proxy.retry_count
= 3
The number of retries to send before giving up, and sending a reject message to the
NAS.