Dell PowerConnect W Clearpass 100 Software 3.9 Deployment Guide - Page 492

Database Module Configuration, advanced.eap = 1, RADIUS Services, Authentication, EAP & 802.1X

Page 492 highlights

Table 60 Authentication Module Configuration Settings (Continued) Value Description mschap.ntlm_auth The module can perform authentication itself, or use a Windows Domain Controller. This configuration directive tells the module to call the ntlm_auth program, which will do the authentication, and return the NT-Key. Note that you MUST have "winbindd" and "nmbd" running on the local machine for ntlm_auth to work. See the ntlm_auth program documentation for details. Database Module Configuration Table 61 Database Modeule Configuration Settings Value Description sql.case_insensitive_usernames = 0 Set this option to 1 to match usernames in the local user database without regard to case. This will allows basic RADIUS authentication to work when the case of the username provided by the NAS is different from the case of the username in the local user database. Note that this may have unexpected effects in certain authorization or accounting contexts, or when creating user accounts. This option does not control how external authentication servers perform username matches; these may be case-sensitive or caseinsensitive depending on the type of server and its configuration. The default and recommended setting is to perform case-sensitive username matching. sql.num_sql_socks = 5 The number of SQL connections to make to the database server. sql.connect_failure_retry_delay = 60 The number of seconds to delay retrying on a failed database connection (per socket). sql.safe_characters = not set A list of characters that may be stored in database fields without being escaped. This may be set to the value "all" to indicate all standard ASCII characters. This string should not include any ASCII characters with a value of 128 or more as this could result in a string with an invalid UTF-8 encoding being sent to the database. sql.simultaneous_stale_time = 86400 The "stale time" determines how much time must elapse without any interim accounting updates before an open session is considered "stale" and will no longer count towards a user's session limit. Stale sessions are displayed in the Active Sessions list using a different state icon. This parameter is measured in seconds; the default corresponds to a value of 24 hours. override.session.radutmp = yes Set this parameter to "yes" to enable session limits in the case where guest accounts are limited to a maximum of one or more concurrent sessions. It is important to ensure that when this configuration option is in effect, the NAS is able to reliably send accounting stop messages. Otherwise, sessions will not be closed and this can lead to the same account being denied access when they are not actually logged in. When this occurs, the user's previous session will be shown as active in the active session list; it can be closed manually here. EAP Module Configuration Set the advanced.eap = 1 option to enable additional EAP types to be selected in the RADIUS Services > Authentication>EAP & 802.1X>EAP Configuration form. 492 | Reference ClearPass Guest 3.9 | Deployment Guide

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336
  • 337
  • 338
  • 339
  • 340
  • 341
  • 342
  • 343
  • 344
  • 345
  • 346
  • 347
  • 348
  • 349
  • 350
  • 351
  • 352
  • 353
  • 354
  • 355
  • 356
  • 357
  • 358
  • 359
  • 360
  • 361
  • 362
  • 363
  • 364
  • 365
  • 366
  • 367
  • 368
  • 369
  • 370
  • 371
  • 372
  • 373
  • 374
  • 375
  • 376
  • 377
  • 378
  • 379
  • 380
  • 381
  • 382
  • 383
  • 384
  • 385
  • 386
  • 387
  • 388
  • 389
  • 390
  • 391
  • 392
  • 393
  • 394
  • 395
  • 396
  • 397
  • 398
  • 399
  • 400
  • 401
  • 402
  • 403
  • 404
  • 405
  • 406
  • 407
  • 408
  • 409
  • 410
  • 411
  • 412
  • 413
  • 414
  • 415
  • 416
  • 417
  • 418
  • 419
  • 420
  • 421
  • 422
  • 423
  • 424
  • 425
  • 426
  • 427
  • 428
  • 429
  • 430
  • 431
  • 432
  • 433
  • 434
  • 435
  • 436
  • 437
  • 438
  • 439
  • 440
  • 441
  • 442
  • 443
  • 444
  • 445
  • 446
  • 447
  • 448
  • 449
  • 450
  • 451
  • 452
  • 453
  • 454
  • 455
  • 456
  • 457
  • 458
  • 459
  • 460
  • 461
  • 462
  • 463
  • 464
  • 465
  • 466
  • 467
  • 468
  • 469
  • 470
  • 471
  • 472
  • 473
  • 474
  • 475
  • 476
  • 477
  • 478
  • 479
  • 480
  • 481
  • 482
  • 483
  • 484
  • 485
  • 486
  • 487
  • 488
  • 489
  • 490
  • 491
  • 492
  • 493
  • 494
  • 495
  • 496
  • 497
  • 498
  • 499
  • 500
  • 501
  • 502
  • 503
  • 504
  • 505
  • 506
  • 507
  • 508
  • 509
  • 510
  • 511
  • 512
  • 513
  • 514
  • 515
  • 516
  • 517
  • 518

492
|
Reference
ClearPass Guest 3.9
|
Deployment Guide
Database Module Configuration
EAP Module Configuration
Set the
advanced.eap = 1
option to enable additional EAP types to be selected in the
RADIUS Services
>
Authentication
>
EAP & 802.1X
>
EAP Configuration
form.
mschap.ntlm_auth
The module can perform authentication itself, or use a Windows Domain
Controller. This configuration directive tells the module to call the ntlm_auth
program, which will do the authentication, and return the NT-Key. Note that
you MUST have “winbindd” and “nmbd” running on the local machine for
ntlm_auth to work. See the ntlm_auth program documentation for details.
Table 61
Database Modeule Configuration Settings
Value
Description
sql.case_insensitive_usernames
= 0
Set this option to 1 to match usernames in the local user database
without regard to case.
This will allows basic RADIUS authentication to
work when the case of the username provided by the NAS is different
from the case of the username in the local user database. Note that this
may have unexpected effects in certain authorization or accounting
contexts, or when creating user accounts.
This option does not control how external authentication servers
perform username matches; these may be case-sensitive or case-
insensitive depending on the type of server and its configuration. The
default and recommended setting is to perform case-sensitive
username matching.
sql.num_sql_socks
= 5
The number of SQL connections to make to the database server.
sql.connect_failure_retry_delay
= 60
The number of seconds to delay retrying on a failed database
connection (per socket).
sql.safe_characters = not set
A list of characters that may be stored in database fields without being
escaped.
This may be set to the value “all” to indicate all standard
ASCII characters. This string should not include any ASCII characters
with a value of 128 or more as this could result in a string with an invalid
UTF-8 encoding being sent to the database.
sql.simultaneous_stale_time
= 86400
The “stale time” determines how much time must elapse without any
interim accounting updates before an open session is considered
“stale” and will no longer count towards a user’s session limit. Stale
sessions are displayed in the Active Sessions list using a different state
icon. This parameter is measured in seconds; the default corresponds
to a value of 24 hours.
override.session.radutmp
= yes
Set this parameter to “yes” to enable session limits in the case where
guest accounts are limited to a maximum of one or more concurrent
sessions. It is important to ensure that when this configuration option is
in effect, the NAS is able to reliably send accounting stop messages.
Otherwise, sessions will not be closed and this can lead to the same
account being denied access when they are not actually logged in.
When this occurs, the user's previous session will be shown as active in
the active session list; it can be closed manually here.
Table 60
Authentication Module Configuration Settings (Continued)
Value
Description