Dell W-Series 228 Instant 6.4.3.1-4.2 User Guide - Page 167

TACACS, CPPM Server, CoA only, TACACS Configuration Parameters

Page 167 highlights

Parameter Description Filter Specify the filter to apply when searching for a user in the LDAP database. The default filter string is (objectclass=*). Key Attribute Specify the attribute to use as a key while searching for the LDAP server. For Active Directory, the value is sAMAccountName Timeout Enter a value between 1 and 30 seconds. The default value is 5. Retry count Enter a value between 1 and 5. The default value is 3. Dead Time Specify a dead time for authentication server in minutes within the range of 1-1440 minutes. The default dead time interval is 5 minutes. When two or more authentication servers are configured on the W-IAP and a server is unavailable, the dead time configuration determines the duration for which the authentication server would be available if the server is marked as unavailable. l TACACS-To configure TACACS server, select the TACACS option and configure the following parameters: Table 33: TACACS Configuration Parameters Parameter Description Name Enter a name for the server. IP address Enter the IP address of the TACACS server. Auth Port Enter aTCP IP port used by the server. The default port number is 49. Shared Key Enter a secret key of your choice to authenticate communication between the TACACS+ client and server. Retype Key Re-enter shared key. Timeout Enter a number between 1 and 30 seconds to indicate the timeout period for TACACS+ requests. The default value is 20 seconds. Retry Count Enter a number between 1 and 5 to indicate the maximum number of authentication attempts. The default value is 3. Dead time Specify a dead time in minutes within the range of 1-1440 minutes. The default dead time interval is 5 minutes. Session Enables or disables session authorization. When enabled, the optional authorization session is authorization turned on for the admin users. By default, session authorization is disabled. You can also add TACACS server by selecting the New option when configuring authentication parameters for management users. For more information, see Configuring Authentication Parameters for Management Users on page 154. l CPPM Server for AirGroup CoA-To configure a CPPM server used for AirGroup CoA (Change of Authorization), select the CoA only checkbox. The RADIUS server is automatically selected. 167 | Authentication and User Management Dell Networking W-Series Instant 6.4.3.1-4.2.0.0 | User Guide

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336
  • 337
  • 338
  • 339
  • 340
  • 341
  • 342
  • 343
  • 344
  • 345
  • 346
  • 347
  • 348
  • 349
  • 350
  • 351
  • 352
  • 353
  • 354
  • 355
  • 356
  • 357
  • 358
  • 359
  • 360
  • 361
  • 362
  • 363
  • 364
  • 365
  • 366
  • 367
  • 368
  • 369
  • 370
  • 371
  • 372
  • 373
  • 374
  • 375
  • 376
  • 377
  • 378
  • 379
  • 380
  • 381
  • 382
  • 383
  • 384
  • 385
  • 386
  • 387
  • 388
  • 389
  • 390
  • 391
  • 392
  • 393
  • 394
  • 395
  • 396
  • 397
  • 398
  • 399
  • 400
  • 401
  • 402
  • 403

167
| Authentication and User Management
Dell Networking W-Series Instant 6.4.3.1-4.2.0.0 | User Guide
Parameter
Description
Filter
Specify the filter to apply when searching for a user in the LDAP database. The default filter string is
(objectclass=*)
.
Key
Attribute
Specify the attribute to use as a key while searching for the LDAP server. For Active Directory, the
value is
sAMAccountName
Timeout
Enter a value between 1 and 30 seconds. The default value is 5.
Retry count
Enter a value between 1 and 5. The default value is 3.
Dead Time
Specify a dead time for authentication server in minutes within the range of 1-1440 minutes. The
default dead time interval is 5 minutes.
When two or more authentication servers are configured on the W-IAP and a server is unavailable,
the dead time configuration determines the duration for which the authentication server would be
available if the server is marked as unavailable.
l
TACACS
—To configure TACACS server, select the
TACACS
option and configure the following parameters:
Parameter
Description
Name
Enter a name for the server.
IP address
Enter the IP address of the TACACS server.
Auth Port
Enter aTCP IP port used by the server. The default port number is 49.
Shared Key
Enter a secret key of your choice to authenticate communication between the TACACS+ client and
server.
Retype Key
Re-enter shared key.
Timeout
Enter a number between 1 and 30 seconds to indicate the timeout period for TACACS+ requests.
The default value is 20 seconds.
Retry Count
Enter a number between 1 and 5 to indicate the maximum number of authentication attempts. The
default value is 3.
Dead time
Specify a dead time in minutes within the range of 1-1440 minutes. The default dead time interval is
5 minutes.
Session
authorization
Enables or disables session authorization. When enabled, the optional authorization session is
turned on for the admin users. By default, session authorization is disabled.
Table 33:
TACACS Configuration Parameters
You can also add TACACS server by selecting the
New
option when configuring authentication parameters for
management users. For more information, see
Configuring Authentication Parameters for Management Users
on page 154
.
l
CPPM Server
for AirGroup CoA—To configure a CPPM server used for AirGroup CoA (Change of
Authorization), select the
CoA only
checkbox. The RADIUS server is automatically selected.