User guide

58 Cyclades® CS Console Server Installation, Administration and User Guide
Configuring authentication servers for logins to the console server and
connected devices
If you are configuring any authentication method other than Local, make sure an authentication
server is set up for that method.
The following is a summary of the things you need to know about setting up authentication servers.
The Cyclades CS console server must be on the same subnet as the authentication server.
Each authentication server must be configured and operational.
The console server administrator should obtain the necessary information from each
authentication server administrator, in order set up and identify those servers on the Cyclades
CS console server.
For example, if LDAP authentication were to be used for logins to the console server for logins to
serial ports, then the console server needs to have network access to an LDAP authentication
server. The administrator needs to perform setup on the console server for both types of
authentication servers.
The administrator completes the appropriate form through the Web Manager Expert - Security -
Authentication to setup an authentication server for every authentication method to be used by the
console server and its ports.
To configure a RADIUS authentication server:
Perform the following procedure to configure a RADIUS authentication server when the console
server or any of its ports are configured to use RADIUS authentication method or any of its
variations (Local/RADIUS, RADIUS/Local or RADIUS/DownLocal).
1. Go to Security - Authentication - RADIUS in Expert mode.
2. Fill in the form according to your local RADIUS server configuration.
3. Click apply changes.
To configure a TACACS+ authentication server:
Perform the following procedure to configure a TACACS+ authentication server when the console
server or any of its ports are configured to use TACACS+ authentication method or any of its
variations (Local/TACACS+, TACACS+/Local or TACACS+/DownLocal).
1. Go to Security - Authentication - TACACS+ in Expert mode. The TACACS+ form displays.
2. Fill in the form according to your local TACACS+ server configuration.
3. To apply Authorization in addition to authentication to the box and ports, select the Enable
Raccess Authorization checkbox.
By default, Raccess Authorization is disabled and no additional authorization is implemented.
When Raccess Authorization is enabled, the authorization level of users trying to access the
console server or its ports using TACACS+ authentication is checked. Users with