7.1

Table Of Contents
You can set up a secondary Radius authentication server to be used for high availability. If the primary
RADIUS server does not respond within the server timeout congured for RADIUS authentication, the
request is routed to the secondary server. When the primary server does not respond, the secondary server
receives all future authentication requests.
Configure RADIUS Authentication in Directories Management
You enable RADIUS software on an authentication manager server. For RADIUS authentication, follow the
vendor's conguration documentation.
Prerequisites
Install and congure the RADIUS software on an authentication manager server. For RADIUS
authentication, follow the vendor's conguration documentation.
You need to know the following RADIUS server information to congure RADIUS on the service.
n
IP address or DNS name of the RADIUS server.
n
Authentication port numbers. Authentication port is usually 1812.
n
Authentication type. The authentication types include PAP (Password Authentication Protocol), CHAP
(Challenge Handshake Authentication Protocol), MSCHAP1, MSCHAP2 (Microsoft Challenge
Handshake Authentication Protocol, versions 1 and 2).
n
RADIUS shared secret that is used for encryption and decryption in RADIUS protocol messages.
n
Specic timeout and retry values needed for RADIUS authentication.
n
Log in to the vRealize Automation console as a tenant administrator.
Procedure
1 Select Administration > Directories Management > Connectors.
2 On the Connectors page, select the Worker link for the connector that is being congured for RADIUS
authentication.
3 Click Auth Adapters and then click RadiusAuthAdapter.
You are redirected to the identity manager sign-in page.
4 Click Edit to congure these elds on the Authentication Adapter page.
Option Action
Name A name is required. The default name is RadiusAuthAdapter. You can change this.
Enable Radius
Adapter
Select this box to enable RADIUS authentication.
Number of
authentication
aempts
allowed
Enter the maximum number of failed login aempts when using RADIUS to log in. The default is
ve aempts.
Number of
aempts to
Radius server
Specify the total number of retry aempts. If the primary server does not respond, the service waits
for the congured time before retrying again.
Radius server
hostname/add
ress
Enter the host name or the IP address of the RADIUS server.
Authenticatio
n port
Enter the Radius authentication port number. This is usually 1812.
Accounting
port
Enter 0 for the port number. The accounting port is not used at this time.
Chapter 2 Configuring Tenant Settings
VMware, Inc. 105