Dell PowerConnect W Clearpass 100 Software External Authentication Servers Sof - Page 5

Configuring RADIUS Authentication, Joining an Active Directory domain

Page 5 highlights

• Use role assigned to local user is the only authorization method available for the local user database. If the user's authentication attempt is successful, the RADIUS server will respond with an Access-Accept message that includes the RADIUS attributes defined for the user's role. • Use attributes from Proxy RADIUS server is an authorization method available only for Proxy RADIUS servers. The RADIUS attributes returned by the external RADIUS server are returned unmodified. • Assign a fixed user role may be used to assign all authenticated users to a particular user role. If the user's authentication attempt is successful, the RADIUS server will respond with an Access-Accept message that includes the RADIUS attributes defined for the fixed role that has been selected for this authentication server. Configuring RADIUS Authentication The RADIUS > Authentication menu contains links to the screens related to configuring authentication: NOTE The RADIUS server's EAP & 802.1X functionality is now located under the RADIUS > Authentication menu. In earlier software releases, this menu option was located directly below the RADIUS Services heading. Joining an Active Directory domain To perform certain types of user authentication, such as using the MS-CHAPv2 protocol to verify a username and password, the RADIUS server must join the domain. The steps required to join the domain are shown below: Navigate to RADIUS > Authentication > Active Directory. The following screen will be displayed: Amigopod |Technical Note External Authentication Servers |5

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13

Amigopod
|Technical Note
External Authentication Servers
|
5
Use role
assigned to local user is the only authorization method available for the local user
database. If the user’s authentication attempt is successful, the RADIUS server will respond
with an Access-Accept message that includes the RADIUS attributes defined for the user’s role.
Use attributes from Proxy RADIUS server is an authorization method available only for Proxy
RADIUS servers. The RADIUS attributes returned by the external RADIUS server are returned
unmodified.
Assign a fixed user role may be used to assign all authenticated users to a particular user role.
If the user’s authentication attempt is successful, the RADIUS server will respond with an
Access-Accept message that includes the RADIUS attributes defined for the fixed role that has
been selected for this authentication server.
Configuring RADIUS Authentication
The
RADIUS
>
Authentication
menu contains links to the screens related to configuring
authentication:
NOTE
The RADIUS server’s EAP & 802.1X functionality is now located under the
RADIUS
>
Authentication
menu. In earlier software releases, this menu option was located directly below
the RADIUS Services heading.
Joining an Active Directory domain
To perform certain types of user authentication, such as using the MS-CHAPv2 protocol to verify a
username and password, the RADIUS server must join the domain.
The steps required to join the domain are shown below:
Navigate to
RADIUS
>
Authentication
>
Active Directory
. The following screen will be
displayed: