User guide
Remote Authentication
68
4. AccountingPort.Thedefaultaccountingportis1813;changeas
required.
5. Timeout(inseconds).Thedefaulttimeoutis1second;changeas
required.ThetimeoutisthelengthoftimetheKXII‐101waitsfora
responsefromtheRADIUSserverbeforesendinganother
authenticationrequest.
6. Retries.Thede
faultnumberofretriesis3;changeasrequired.Thisis
thenumberoftimestheKXII‐101willsendanauthentication
requesttotheRADIUSserver.
7. GlobalAuthenticationType.Choosefromamongtheoptionsinthe
drop‐downlist:
PAP.WithPAP,passwordsaresentasplaintext.PA
Pisnot
interactive;theusernameandpasswordaresentasonedata
packageonceaconnectionisestablished,ratherthantheserver
sendingaloginpromptandwaitingforaresponse.
CHAP.WithCHAPauthenticationcanberequestedbythe
serveratanytime.CHAPprovidesmoresec
uritythanPAP.
Returning User Group Information via RADIUS
WhenaRADIUSauthenticationattemptsucceeds,theKXII‐101device
determinesthepermissionsforagivenuserbasedonthepermissionsof
theuserʹsgroup.
YourremoteRADIUSservercanprovidetheseusergroupnamesby
returninganattribute,implementedasaRADIUSFILTER‐ID.The
FILTER‐IDshouldbef
ormattedasfollows:
Raritan:G{GROUP_NAME}
whereGROUP_NAMEisastring,denotingthenameofthegroupto
whichtheuserbelongs.
RADIUS Communication Exchange Specifications
TheKXII‐101unitsendsthefollowingRADIUSattributestoyour
RADIUSserver:
Attribute Data
Login
Access‐Request(1)
NAS‐Port‐Type(61) VIRTUAL(5)fornetworkconnections.