EasyManua.ls Logo

ZyXEL Communications UAG5100 - Page 400

ZyXEL Communications UAG5100
617 pages
To Next Page IconTo Next Page
To Next Page IconTo Next Page
To Previous Page IconTo Previous Page
To Previous Page IconTo Previous Page
Loading...
Chapter 35 User/Group
UAG Series User’s Guide
400
Note: The default admin account is always authenticated locally, regardless of the
authentication method setting. (See Chapter 43 on page 464 for more information
about authentication methods.)
Ext-User Accounts
Set up an ext-user account if the user is authenticated by an external server and you want to set
up specific policies for this user in the UAG. If you do not want to set up policies for this user, you
do not have to set up an ext-user account.
All ext-user users should be authenticated by an external server, such as RADIUS. If the UAG tries
to use the local database to authenticate an ext-user, the authentication attempt always fails.
(This is related to AAA servers and authentication methods, which are discussed in Chapter 42 on
page 459 and Chapter 43 on page 464, respectively.)
Note: If the UAG tries to authenticate an ext-user using the local database, the attempt
always fails.
Once an ext-user user has been authenticated, the UAG tries to get the user type (see Table 177
on page 399) from the external server. If the external server does not have the information, the
UAG sets the user type for this session to User.
For the rest of the user attributes, such as reauthentication time, the UAG checks the following
places, in order.
1 User account in the remote server.
2 User account (Ext-User) in the UAG.
3 Default user account for RADIUS users (radius-users) in the UAG.
See Setting up User Attributes in an External Server on page 413 for a list of attributes and how to
set up the attributes in an external server.
Ext-Group-User Accounts
Ext-Group-User accounts are similar to ext-user accounts but allow you to group users by the
value of the group membership attribute configured for the RADIUS server. See Section 42.2.1 on
page 460 for more on the group membership attribute.
Dynamic-Guest Accounts
Dynamic guest accounts are guest accounts, but are created dynamically and stored in the UAG’s
local user database. A dynamic guest account has a dynamically-created user name and password.
A dynamic guest account user can access the UAG’s services only within a given period of time and
will become invalid after the expiration date/time.
guest-manager Create dynamic guest accounts WWW
pre-subscriber Access network services Web Authentication Portal
dynamic-guest Access network services Web Authentication Portal
Table 177 Types of User Accounts (continued)
TYPE ABILITIES LOGIN METHOD(S)

Table of Contents

Other manuals for ZyXEL Communications UAG5100

Related product manuals