Dell PowerConnect W Clearpass 100 Software 3.7 Deployment Guide - Page 416

Database Module Configuration, advanced.eap = 1, RADIUS Services, Authentication, EAP & 802.1X

Page 416 highlights

Database Module Configuration Table 52 Database Modeule Configuration Settings Value Description sql.case_insensitive_usernames = 0 Set this option to 1 to match usernames in the local user database without regard to case. This will allows basic RADIUS authentication to work when the case of the username provided by the NAS is different from the case of the username in the local user database. Note that this may have unexpected effects in certain authorization or accounting contexts, or when creating user accounts. This option does not control how external authentication servers perform username matches; these may be case-sensitive or caseinsensitive depending on the type of server and its configuration. The default and recommended setting is to perform case-sensitive username matching. sql.num_sql_socks = 5 The number of SQL connections to make to the database server. sql.connect_failure_retry_delay = 60 The number of seconds to delay retrying on a failed database connection (per socket). sql.safe_characters = not set A list of characters that may be stored in database fields without being escaped. This may be set to the value "all" to indicate all standard ASCII characters. This string should not include any ASCII characters with a value of 128 or more as this could result in a string with an invalid UTF-8 encoding being sent to the database. sql.simultaneous_stale_time = 86400 The "stale time" determines how much time must elapse without any interim accounting updates before an open session is considered "stale" and will no longer count towards a user's session limit. Stale sessions are displayed in the Active Sessions list using a different state icon. This parameter is measured in seconds; the default corresponds to a value of 24 hours. override.session.radutmp = yes Set this parameter to "yes" to enable session limits in the case where guest accounts are limited to a maximum of one or more concurrent sessions. It is important to ensure that when this configuration option is in effect, the NAS is able to reliably send accounting stop messages. Otherwise, sessions will not be closed and this can lead to the same account being denied access when they are not actually logged in. When this occurs, the user's previous session will be shown as active in the active session list; it can be closed manually here. EAP Module Configuration Set the advanced.eap = 1 option to enable additional EAP types to be selected in the RADIUS Services > Authentication>EAP & 802.1X>EAP Configuration form. The following EAP module options are usually not required, as EAP configuration can be performed using the WebUI. For EAP documentation, See "EAP and 802.1X Authentication" in the RADIUS Services chapter for further details. Table 53 Optional EAP Module Options Function Description advanced.eap = 1 module.eap = yes Enable additional EAP types in the EAP Configuration form. Extensible Authentication Protocol authentication. 416 | Reference Amigopod 3.7 | Deployment Guide

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336
  • 337
  • 338
  • 339
  • 340
  • 341
  • 342
  • 343
  • 344
  • 345
  • 346
  • 347
  • 348
  • 349
  • 350
  • 351
  • 352
  • 353
  • 354
  • 355
  • 356
  • 357
  • 358
  • 359
  • 360
  • 361
  • 362
  • 363
  • 364
  • 365
  • 366
  • 367
  • 368
  • 369
  • 370
  • 371
  • 372
  • 373
  • 374
  • 375
  • 376
  • 377
  • 378
  • 379
  • 380
  • 381
  • 382
  • 383
  • 384
  • 385
  • 386
  • 387
  • 388
  • 389
  • 390
  • 391
  • 392
  • 393
  • 394
  • 395
  • 396
  • 397
  • 398
  • 399
  • 400
  • 401
  • 402
  • 403
  • 404
  • 405
  • 406
  • 407
  • 408
  • 409
  • 410
  • 411
  • 412
  • 413
  • 414
  • 415
  • 416
  • 417
  • 418
  • 419
  • 420
  • 421
  • 422
  • 423
  • 424
  • 425
  • 426
  • 427
  • 428
  • 429
  • 430
  • 431
  • 432
  • 433
  • 434
  • 435
  • 436
  • 437
  • 438

416
| Reference
Amigopod 3.7
|
Deployment Guide
Database Module Configuration
EAP Module Configuration
Set the
advanced.eap = 1
option to enable additional EAP types to be selected in the
RADIUS Services
>
Authentication
>
EAP & 802.1X
>
EAP Configuration
form.
The following EAP module options are usually not required, as EAP configuration can be performed using
the WebUI. For EAP documentation,
See
“EAP and 802.1X Authentication”
in the RADIUS Services
chapter for further details.
Table 52
Database Modeule Configuration Settings
Value
Description
sql.case_insensitive_usernames
= 0
Set this option to 1 to match usernames in the local user database
without regard to case.
This will allows basic RADIUS authentication to
work when the case of the username provided by the NAS is different
from the case of the username in the local user database. Note that this
may have unexpected effects in certain authorization or accounting
contexts, or when creating user accounts.
This option does not control how external authentication servers
perform username matches; these may be case-sensitive or case-
insensitive depending on the type of server and its configuration. The
default and recommended setting is to perform case-sensitive
username matching.
sql.num_sql_socks
= 5
The number of SQL connections to make to the database server.
sql.connect_failure_retry_delay
= 60
The number of seconds to delay retrying on a failed database
connection (per socket).
sql.safe_characters = not set
A list of characters that may be stored in database fields without being
escaped.
This may be set to the value “all” to indicate all standard
ASCII characters. This string should not include any ASCII characters
with a value of 128 or more as this could result in a string with an invalid
UTF-8 encoding being sent to the database.
sql.simultaneous_stale_time
= 86400
The “stale time” determines how much time must elapse without any
interim accounting updates before an open session is considered
“stale” and will no longer count towards a user’s session limit. Stale
sessions are displayed in the Active Sessions list using a different state
icon. This parameter is measured in seconds; the default corresponds
to a value of 24 hours.
override.session.radutmp
= yes
Set this parameter to “yes” to enable session limits in the case where
guest accounts are limited to a maximum of one or more concurrent
sessions. It is important to ensure that when this configuration option is
in effect, the NAS is able to reliably send accounting stop messages.
Otherwise, sessions will not be closed and this can lead to the same
account being denied access when they are not actually logged in.
When this occurs, the user's previous session will be shown as active in
the active session list; it can be closed manually here.
Table 53
Optional EAP Module Options
Function
Description
advanced.eap
= 1
Enable additional EAP types in the EAP Configuration form.
module.eap
= yes
Extensible Authentication Protocol authentication.