628| Managemen t Access DellPowerConnect W- Series ArubaOS 6.2 | User Guide
Configuring RAD IUS Server Auth entication with V SA
In this scenario, an externalRAD IUS serverauthenticates management users and returnst o the controllerthe Dell
vendor-specificat tribute (VSA) calledD ell-Admin-Rolethat contains the name of the management role fort heuser.
The authenticated useris placed into t hemanagement role specified by the VSA.
The controllerconfiguration is identical to the "Configuring RADIUS Server Username and Password
Authentication" on page 627. The only difference is the configuration of the VSA on the RADIUS server. Ensure
that the valueo ft heV SA returnedby the RAD IUS serveris o neo ft hepredefined management roles.Otherwise, the
userwi llhave
no
access to the controller.
Configuring RAD IUS Server Auth entication with S erver Derivation Ru le
NOTE: Dell controllersdo not m ake use of any returned attributesfrom a TACACS+server.
A RADIUS server can return to the controller a standard RADIUS attribute that contains o neo f the following
values:
lThe nameof the management role for the user
lA value from which a managementrole can be derived
For either situation, configure a server-derivation rulefor the server group.
In the followingexample, the RADIUS server returns the attribute Class to the controller. Thevalue of the attribute
can be either“ root” or “network-operations” dependingupon the user; the returned valueis the role granted to the
user.
NOTE:Ensure that the value of the attribute returnedby the RADIUS server is one of the predefined management roles. Otherwise,
themanagem entuser wi ll not be granted accessto the controller.
In the WebUI
1. N avigate to the Configuration > Security > Authentication > Servers page.
2. Select RADIUS Server to display the Radius Server List.
a. To configurea R ADIUS server, enterthe name for the server (for example,rad1) and click Add.
b. Select the name to configure server parameters,such as IP address. Selectthe Mode checkbox to acti vate the
server.
c. Click Apply.
3. Select Server Group to display the Server Group list.
a. Enter the name of the new server group (for example,corp_rad) and click Add.
b. Select the name to configure the server group.
c. UnderServers, click New to add a server to the group.
d. Select a server from the drop-down menu and click Add Server.
e. UnderServer Rules, click New to add a server rule.
f. For Condition, select Class from the scrolling list. Select value-of from the drop-down menu.Select Set Role
fromt he drop-downmenu.
g. Click Add.
h. Click Apply.
4. N avigate to the Configuration > Management > Administration page.