User guide

Remote Authentication
68
4. AccountingPort.Thedefaultaccountingportis1813;changeas
required.
5. Timeout(inseconds).Thedefaulttimeoutis1second;changeas
required.ThetimeoutisthelengthoftimetheKXII101waitsfora
responsefromtheRADIUSserverbeforesendinganother
authenticationrequest.
6. Retries.Thede
faultnumberofretriesis3;changeasrequired.Thisis
thenumberoftimestheKXII101willsendanauthentication
requesttotheRADIUSserver.
7. GlobalAuthenticationType.Choosefromamongtheoptionsinthe
dropdownlist:
PAP.WithPAP,passwordsaresentasplaintext.PA
Pisnot
interactive;theusernameandpasswordaresentasonedata
packageonceaconnectionisestablished,ratherthantheserver
sendingaloginpromptandwaitingforaresponse.
CHAP.WithCHAPauthenticationcanberequestedbythe
serveratanytime.CHAPprovidesmoresec
uritythanPAP.
Returning User Group Information via RADIUS
WhenaRADIUSauthenticationattemptsucceeds,theKXII101device
determinesthepermissionsforagivenuserbasedonthepermissionsof
theuserʹsgroup.
YourremoteRADIUSservercanprovidetheseusergroupnamesby
returninganattribute,implementedasaRADIUSFILTERID.The
FILTERIDshouldbef
ormattedasfollows:
Raritan:G{GROUP_NAME}
whereGROUP_NAMEisastring,denotingthenameofthegroupto
whichtheuserbelongs.
RADIUS Communication Exchange Specifications
TheKXII101unitsendsthefollowingRADIUSattributestoyour
RADIUSserver:
Attribute Data
Login
AccessRequest(1)
NASPortType(61) VIRTUAL(5)fornetworkconnections.