Schneider Electric AP9635 Configuring the Radius Server, Summary of the configuration procedure

Page 61

Configuring the RADIUS Server

Summary of the configuration procedure

You must configure your RADIUS server to work with the Management Card.

For examples of the RADIUS users file with Vendor Specific Attributes (VSAs) and an example of an entry in the dictionary file on the RADIUS server, see the Security Handbook.

1.Add the IP address of the Management Card to the RADIUS server client list (file).

2.Users must be configured with Service-Type attributes unless Vendor Specific Attributes (VSAs) are defined. If no Service-Type attributes are configured, users will have read-only access (on the Web interface only).

See your RADIUS server documentation for information about the RADIUS users file, and see the Security Handbook for an example.

3.Vendor Specific Attributes (VSAs) can be used instead of the Service-Type attributes provided by the RADIUS server. VSAs require a dictionary entry and a RADIUS users file. In the dictionary file, define the names for the ATTRIBUTE and VALUE keywords, but not for the numeric values. If you change numeric values, RADIUS authentication and authorization will fail. VSAs take precedence over standard RADIUS attributes.

Configuring a RADIUS server on UNIX® with shadow passwords

If UNIX shadow password files are used (/etc/passwd) with the RADIUS dictionary files, the following two methods can be used to authenticate users:

• If all UNIX users have administrative privileges, add the following to the RADIUS “user” file. To allow only Device Users, change the APC-Service-Type to Device.

DEFAULTAuth-Type = System

APC-Service-Type = Admin

Add user names and attributes to the RADIUS “user” file, and verify the password against /etc/ passwd. The following example is for users bconners and thawk:

bconners

Auth-Type = System

 

 

APC-Service-Type

=

Admin

thawk

Auth-Type = System

 

 

APC-Service-Type

=

Device

Supported RADIUS servers

American Power Conversion supports FreeRADIUS and Microsoft IAS 2003. Other commonly available RADIUS applications may work but have not been fully tested by American Power Conversion.

Network Management Card User’s Guide

52

Image 61
Contents User’s Guide 동봉된 CD 안에 한국어 매뉴얼이 있습니다 Contents Web Interface Monitor the UPS and Configure Shutdowns Logs Administration Notification Troubleshooting Appendix a List of Supported Commands Introduction FeaturesProduct Description Initial setup Internal Management FeaturesNetwork management features OverviewTypes of user accounts Access priority for logging onHow to Recover from a Lost Password Description Front PanelCondition Description Status LEDLink-RX/TX 10/100 LED Resetting the network timer Watchdog FeaturesNetwork interface watchdog mechanism How To Log On Command Line InterfaceRemote access to the command line interface Sample main screen Main ScreenInformation and status fields Two fields report when you logged in, by date and time Entering commands Using the Command Line InterfaceCommand syntax Code Error message Command Response CodesSyntax examples Alarmcount Command DescriptionsAbout Option Arguments DescriptionOption Argument Description BootDate ConsoleArgument Description DeleteDir DnsKey Description EventlogExit FormatOption Argument Definition FtpHelp ModbusNtp NetstatPing Prompt PortSpeedQuit Radius RebootSnmp, snmp3 ResetToDefSystem Tcpip6 TcpipTls Ups UioUser XferINI WebXferStatus Introduction Web InterfaceSupported Web browsers URL address formats Error Message Browser Cause of the ErrorQuick status icons HomeIcon Description Recent Device EventsTabs How to Use the Tabs, Menus, and LinksMenus Quick LinksOverview Monitor the UPS and Configure ShutdownsOperating state Operating State Icon DescriptionRecent UPS Events StatusModel-specific status displayed PowerChute Network Shutdown clients PowerChute OptionParameter Description PowerChute Network Shutdown configuration parametersAbout Option Heading Displayed Information Environmental MonitoringDetailed status and configuration Temperature and HumidityBrief status Threshold DescriptionUPS Network Management Card 2 User’s Guide Input Contacts About Output RelayConfiguring an output to respond to an event Configuring the Control PolicyConfiguring the UPS or output to respond to an input alarm Use the Event and Data Logs LogsEvent log Launch Log in New Window buttonData log To display the data log Logs Data log To set the data collection interval Logs Data interval How to use FTP or SCP to retrieve log files Scp username@hostnameoripaddressevent.csv ./event.csv Syslog servers Setting user access Administration SecurityAuthentication Local UsersRadius Radius Setting DefinitionSummary of the configuration procedure Configuring the Radius ServerConfiguring a Radius server on Unix with shadow passwords Supported Radius serversInactivity Timeout TCP/IP and Communication Settings Administration Network FeaturesTCP/IP settings Setting DescriptionAPC Cookie. Tag 1, Len 4, Data 1APC Dhcp response optionsPing Response DNS Port SpeedQuery Type Selected Query Question to Use Option Description WebConsole SNMPv1 SnmpSNMPv3 Modbus FTP Server Configuring event actions Administration NotificationEvent Actions Types of notificationNetwork Management Card User’s Guide Mail notification Active, Automatic, Direct NotificationIdentify up to four e-mail recipients Snmp Trap Test Snmp trapsSetting Definition Remote Monitoring ServiceSyslog Syslog Settings Path Logs Syslog settings Identification Administration General OptionsSet the Date and Time MethodDaylight saving Use an .ini FileChange the default temperature scale Event Log, Temperature Units, and Log-InSpecify a default login Color-code event log textConfigure Links Reset the Management CardAbout the Management Card Action DefinitionCapabilities, Requirements, and Installation Device IP Configuration WizardHow to use the Wizard to configure TCP/IP settings InstallationUse the Wizard Configure the basic TCP/IP settings remotelySelect Remotely over the network, and click Next Select Locally through the serial port, and click Next Configure or reconfigure the TCP/IP settings locallySummary of the procedure How to Export Configuration SettingsContents of the .ini file Detailed proceduresFtp put filename.ini Event and its error messages Upload Event and Error MessagesMessages in config.ini Errors generated by overridden valuesRelated Topics File Transfers How to Upgrade FirmwareBenefits of upgrading firmware Firmware files Network Management CardFirmware File Transfer Methods Use FTP or SCP to upgrade one Management CardHow to upgrade multiple Management Cards Use Xmodem to upgrade one Management Card Verify the version numbers of installed firmware Verifying Upgrades and UpdatesUse a USB drive to transfer the files Verify the success or failure of the transferAdding and Changing Language Packs Management Card Access Problems TroubleshootingProblem Solution GET Snmp IssuesAppendix a List of Supported Commands Network Management Card User’s Guide Network Management Card User’s Guide Terms of warranty Two-Year Factory WarrantyNon-transferable warranty Exclusions Warranty claims 990-3197B-001 2011 APC Worldwide Customer Support