EasyManua.ls Logo

FlexDSL ORION 3 - RADIUS Server Setup with Defined Service-Type Attribute

FlexDSL ORION 3
160 pages
Print Icon
To Next Page IconTo Next Page
To Next Page IconTo Next Page
To Previous Page IconTo Previous Page
To Previous Page IconTo Previous Page
Loading...
User Manual LTU Orion 3
39
3.2.2.9.3 RADIUS Server setup with defined Service-Type Attribute
Alternatively, we can setup the freeradius server with Service-Type Attribute. Currently the
following Service-types are supported:
Type 6: Administrative; modem grants access equal to FlexDSL-Rights = ALL
Type 7: NAS Prompt; modem grants access equal to FlexDSL-Rights += TEST, += STATUS
User configuration. File users
User records are in /etc/freeradius/users
# Orion3 User with Administration rights
ORION3ADMIN Cleartext-Password := "AdminPass"
Framed-IP-Address = 192.168.169.0,
Framed-IP-Netmask = 255.255.255.0,
Service-Type = Administrative-user
# Orion3 User with Read-only rights
ORION3OPERATOR Cleartext-Password := "OperatorPass"
Framed-IP-Address = 192.168.169.0,
Framed-IP-Netmask = 255.255.255.0,
Service-Type = NAS-Prompt-user
NOTE: Don`t forget to restart freeradius server after changing configuration using
sudo service freeradius restart command.
3.2.2.9.4 Configuring User Access Rights
The <Vendor-Specific> or <FlexDSL-Rights> or <Service-Type> field in RADIUS configuration
tells the client what access rights the user has. It is possible to grant or discard access to various
commands and menu items of the modem device. All commands of the CLI are divided into 3
levels. Selection of upper level means that the commands from low levels will be selected too.
Some commands are available for every user, they can’t be revoked.
Privileges
Hierarchy Levels
Description
Related commands
Top
Level
Group
Subgroup
ALL
Commands of
this level are
available for
everyone. No
additional
authorization is
required
ALARM
ALARM T
DISCONNECT
LINKCLEAR
TLM
SENSOR
ACO
SOFTINFO
CONTROL
[CTRL]
Operation of
remote devices
CONNECT
LINK
TEST
[T]
Test of the
device
LOOP1
LOOP2
STARTAL
RESTART
PING
MACTABLE
MACTABLE C
BERT Submenu
ADMIN
[A]
Administration of
the device
DIFF
DUMP
SERNUM
LICENSE
ACO change
RESET
SOFTUPDATE
SOFTCONFIRM
ID
RESPONSE
PASSWORD
NMTHR

Table of Contents

Related product manuals