Specifications

Chapter 10 User Groups
If you selected Internal as the authentication service, go to step 4.
If you selected any other type of authentication service, go to step 5.
NOTE: If you are adding a group to the TACACS+ authentication service, see TACACS+ external authentication services on page 87 for more
information.
4. The Type in Internal Group Name window will open. Type the name for the new user group you wish to create. User-
defined user group names may contain up to 256 characters. User-defined user group names are case-preserving. Go
to step 6.
5. The Specify External Group window opens. Complete one of the following steps, then click Next:
Click Specify a group on external authentication service and type the name of the group in the field.
User group names may contain up to 256 non-case sensitive characters. User group names are case-
preserving if the user group on the external authentication server is case sensitive. See Group naming in
external authentication services on page 84.
Click Import the external group - Everyone to consider any user on the external authentication server as a
member of this user group.
Click Find a group on external authentication service to choose from the list of groups on the external
authentication service. If the list of groups contains more than 5000 entries, a message will indicate that not all
items are displayed.
You may filter the list by using the Filter button and the adjacent text field. If you are using an Active
Directory Server, you can choose the filter method.
Click Filter in DTX Control server (legacy) to use a traditional filtering method.
-or-
Click Filter in Active Directory Server to use a modified filtering method that only provides matches to
the filter string based on the common name (CN) of the group. This filter uses LDAP search syntax. This
method passes the filter to the AD server allowing the AD server to return the matches, which provides
faster results than the legacy filter method.
Select one or more external authentication service groups from the list.
6. Select a role for the user group(s).
7. Click Finish.
TACACS+ external authentication services
To add a TACACS+ user group:
1. Click the Users tab. Click Groups in the top navigation bar. Click User-Defined in the side navigation bar. The User
Groups - User Defined window will open.
2. Click Add. The Add User Group wizard will appear.
3. The Select Authentication Service window will open. This window lists all authentication services that may be used
to authenticate the user group when the user logs in. Select an appropriate TACACS+ authentication service from the
list. Click Next.
4. If the TACACS+ service you selected is configured to use the privilege level attribute method, the Specify External
Group Name window will open and display a list of privilege levels 0-15 (the higher the number, the higher the level of
access).
Page 87 724-746-5500 | blackbox.com