Lantronix EMG 8500 EMG User Guide - Page 319

Custom User Menu Commands, Key Sequences, Dial-back

Page 319 highlights

14: User Authentication 2. Enter the following: Enable TACACS+ Displays selected if you enabled this method on the User Authentication page. If you want to set up this authentication method but not enable it immediately, clear the checkbox. You can enable TACACS+ here or on the first User Authentication page. If you enable TACACS+ here, it automatically displays at the end of the order of precedence on the User Authentication page. TACACS+ Servers 1-3 IPv4 or IPv6 address or host name of up to three TACACS+ servers. Secret/Retype Secret Shared secret for message encryption between the EMG and the TACACS+ server. Enter an alphanumeric secret of up to 127 characters. Encrypt Messages Select the checkbox to encrypt messages between the EMG unit and the TACACS+ server. Selected by default. Authentication Service The type of service used to pass the authentication tokens (e.g., login and password) between the EMG and the TACACS+ server. Options are: ASCII Login (login and password are transmitted in clear, unencrypted text), PPP/PAP (login and password are transmitted in clear, unencrypted text via a PAP protocol packet), and PPP/CHAP (the TACACS+ server sends a challenge that consists of a session ID and an arbitrary challenge string, and the user name and password are encrypted before they are sent back to the server). PPP/PAP is the default. Service The service to use when sending a TACACS+ authorization message to the server to obtain an authenticated user's priv_lvl. The priv_lvl is used to assign a EMG custom group to the authenticated user for permissions and port rights (see TACACS+ Groups). Suggested values are "slip", "ppp", "arap", "shell", "ttydaemon", "connection", "system" and "firewall". The default is "shell". Protocol The optional protocol associated with the Service, which is included in the TACACS+ authorization message sent to the server to obtain an authenticated user's priv_lvl. The priv_lvl is used to assign a EMG custom group to the authenticated user for permissions and port rights (see TACACS+ Groups). Suggested values are "lcp", "ip", "ipx", "atalk", "vines", "lat", "xremote", "tn3270", "telnet", "rlogin", "pad", "vpdn", "ftp", "http", "deccp", "osicp" and "unknown". Timeout The timeout in seconds when attempting to connect to a TACACS+ server. Timeout range is 1 to 10 seconds. 5 seconds is the default. Custom Menu If custom menus have been created (see Custom User Menu Commands), you can assign a default custom menu to TACACS+ users. Escape Sequence A single character or a two-character sequence that causes the EMG to leave direct (interactive) mode. (To leave listen mode, press any key.) A suggested value is Esc+A (escape key, then uppercase "A" performed quickly but not simultaneously). You would specify this value as \x1bA, which is hexadecimal (\x) character 27 (1B) followed by an A. This setting allows the user to terminate the connect direct command on the command line interface when the endpoint of the command is deviceport, tcp, or udp. Break Sequence A series of 1-10 characters users can enter on the command line interface to send a break signal to the external device. A suggested value is Esc+B (escape key, then uppercase "B" performed quickly but not simultaneously). You would specify this value as \x1bB, which is hexadecimal (\x) character 27 (1B) followed by a B. See Key Sequences for notes on key sequence precedence and behavior. Enable for Dial-back Select to grant a user Dial-back access. Users with dial-back access can dial into the EMG unit and enter their login and password. Once the EMG authenticates them, the modem hangs up and dials them back. Disabled by default. EMG™ Edge Management Gateway User Guide 319

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336
  • 337
  • 338
  • 339
  • 340
  • 341
  • 342
  • 343
  • 344
  • 345
  • 346
  • 347
  • 348
  • 349
  • 350
  • 351
  • 352
  • 353
  • 354
  • 355
  • 356
  • 357
  • 358
  • 359
  • 360
  • 361
  • 362
  • 363
  • 364
  • 365
  • 366
  • 367
  • 368
  • 369
  • 370
  • 371
  • 372
  • 373
  • 374
  • 375
  • 376
  • 377
  • 378
  • 379
  • 380
  • 381
  • 382
  • 383
  • 384
  • 385
  • 386
  • 387
  • 388
  • 389
  • 390
  • 391
  • 392
  • 393
  • 394
  • 395
  • 396
  • 397
  • 398
  • 399
  • 400
  • 401
  • 402
  • 403
  • 404
  • 405
  • 406
  • 407
  • 408
  • 409
  • 410
  • 411
  • 412
  • 413
  • 414
  • 415
  • 416
  • 417
  • 418
  • 419
  • 420
  • 421
  • 422
  • 423
  • 424
  • 425
  • 426
  • 427
  • 428
  • 429
  • 430
  • 431
  • 432
  • 433
  • 434
  • 435
  • 436
  • 437
  • 438
  • 439
  • 440
  • 441
  • 442
  • 443
  • 444
  • 445
  • 446
  • 447
  • 448
  • 449
  • 450
  • 451
  • 452
  • 453
  • 454
  • 455
  • 456
  • 457
  • 458
  • 459
  • 460
  • 461
  • 462
  • 463
  • 464
  • 465
  • 466
  • 467
  • 468
  • 469
  • 470
  • 471
  • 472
  • 473
  • 474
  • 475
  • 476
  • 477
  • 478
  • 479
  • 480
  • 481
  • 482
  • 483
  • 484
  • 485
  • 486
  • 487
  • 488
  • 489
  • 490
  • 491
  • 492
  • 493
  • 494
  • 495

14: User Authentication
EMG™ Edge Management Gateway User Guide
319
2.
Enter the following:
Enable TACACS+
Displays selected if you enabled this method on the User Authentication page. If
you want to set up this authentication method but not enable it immediately, clear
the checkbox.
You can enable TACACS+ here or on the first User Authentication page. If you
enable TACACS+ here, it automatically displays at the end of the order of
precedence on the User Authentication page.
TACACS+ Servers 1-3
IPv4 or IPv6 address or host name of up to three TACACS+ servers.
Secret/Retype Secret
Shared secret for message encryption between the EMG and the TACACS+
server. Enter an alphanumeric secret of up to 127 characters.
Encrypt Messages
Select the checkbox to encrypt messages between the EMG unit and the
TACACS+ server. Selected by default.
Authentication
Service
The type of service used to pass the authentication tokens (e.g., login and
password) between the EMG and the TACACS+ server. Options are:
ASCII
Login
(login and password are transmitted in clear, unencrypted text),
PPP/PAP
(login and password are transmitted in clear, unencrypted text via a PAP protocol
packet), and
PPP/CHAP
(the TACACS+ server sends a challenge that consists of
a session ID and an arbitrary challenge string, and the user name and password
are encrypted before they are sent back to the server). PPP/PAP is the default.
Service
The service to use when sending a TACACS+ authorization message to the
server to obtain an authenticated user's priv_lvl. The priv_lvl is used to assign a
EMG custom group to the authenticated user for permissions and port rights (see
TACACS+ Groups). Suggested values are "slip", "ppp", "arap", "shell", "tty-
daemon", "connection", "system" and "firewall". The default is "shell".
Protocol
The optional protocol associated with the Service, which is included in the
TACACS+ authorization message sent to the server to obtain an authenticated
user's priv_lvl. The priv_lvl is used to assign a EMG custom group to the
authenticated user for permissions and port rights (see TACACS+ Groups).
Suggested values are "lcp", "ip", "ipx", "atalk", "vines", "lat", "xremote", "tn3270",
"telnet", "rlogin", "pad", "vpdn", "ftp", "http", "deccp", "osicp" and "unknown".
Timeout
The timeout in seconds when attempting to connect to a TACACS+ server.
Timeout range is 1 to 10 seconds. 5 seconds is the default.
Custom Menu
If custom menus have been created (see
Custom User Menu Commands
), you
can assign a default custom menu to TACACS+ users.
Escape Sequence
A single character or a two-character sequence that causes the EMG to leave
direct (interactive) mode. (To leave listen mode, press any key.)
A suggested value is
Esc+A
(escape key, then uppercase "A" performed quickly
but not simultaneously). You would specify this value as
\
x1bA
, which is
hexadecimal (
\
x
) character 27 (
1B
) followed by an
A
.
This setting allows the user to terminate the
connect direct
command on
the command line interface when the endpoint of the command is
deviceport
,
tcp
, or
udp
.
Break
Sequence
A series of 1-10 characters users can enter on the command line interface to send
a break signal to the external device. A suggested value is
Esc+B
(escape key,
then uppercase “B” performed quickly but not simultaneously). You would specify
this value as
\
x1bB
, which is hexadecimal (
\
x
) character 27 (
1B
) followed by a
B
.
See
Key Sequences
for notes on key sequence precedence and behavior.
Enable for Dial-back
Select to grant a user
Dial-back
access. Users with dial-back access can dial into
the EMG unit and enter their login and password. Once the EMG
authenticates
them, the modem hangs up and dials them back. Disabled by default.