Management
Management tool
2-4
Administrative user authentication
Login credentials for administrative users can be verified using local account settings and/or
an external RADIUS sever.
Local account settings: A single manager and operator account can be configured
locally under Manager account and Operator account on this page.
RADIUS server: Using a RADIUS server enables you to have multiple accounts, each
with a unique login name and password. Identify manager accounts using the vendor
specific attribute web-administrative-role. Valid values for this attribute are Manager
and Operator. For attribute information, see Administrator attributes on page 15-31.
To use a RADIUS server, you must define a RADIUS profile on the Controller >>
Authentication > RADIUS profiles page.
If both options are enabled, the RADIUS server is always checked first.
Authenticating administrative credentials using an external RADIUS
server
Configure RADIUS authentication as follows:
1. Define an account for the administrator on the RADIUS server. See Administrator
attributes on page 15-31.
2. On the controller, create a RADIUS profile that will connect the controller to the RADIUS
server. See Configuring a RADIUS server profile on the controller on page 11-6.
3. Under Administrator authentication, set Authenticate via to the RADIUS profile you
created. In this example, the profile is called Rad1.
4. Test the RADIUS account to make sure it is working before you save your changes.
Specify the appropriate username and password and select Test.
(As a backup measure you can choose to enable Local. This will allow you to log in using
the local account if the connection to the RADIUS server is unavailable.)