Juniper Networks J-Series manual Creating a Remote Template Account

Models: J-Series

1 332
Download 332 pages 610 b
Page 41
Image 41

Chapter 1: Managing User Authentication and Access

Creating a Remote Template Account

You can create a remote template that is applied to users authenticated by RADIUS or TACACS+ that do not belong to a local template account.

By default, the JUNOS software uses the remote template account when

The authenticated user does not exist locally on the Services Router.

The authenticated user's record in the RADIUS or TACACS+ server specifies local user, or the specified local user does not exist locally on the router.

The procedure provided in this section creates a sample user named remote that belongs to the operator login class.

To create a remote template account:

1.Navigate to the top of the configuration hierarchy in either the J-Web or CLI configuration editor.

2.Perform the configuration tasks described in Table 16 on page 19.

3.If you are finished configuring the network, commit the configuration.

To completely set up RADIUS or TACACS+ authentication, you must configure at least one RADIUS or TACACS+ server and specify a system authentication order.

4.Go on to one of the following procedures:

To configure a RADIUS server, see “Setting Up RADIUS Authentication” on page 12.

To configure a TACACS+ server, see “Setting Up TACACS+ Authentication” on page 13.

To specify a system authentication order, see “Configuring Authentication Order” on page 15.

Table 16: Creating a Remote Template Account

Task

J-Web Configuration Editor

Navigate to the System Login

1.

In the J-Web interface, select

level in the configuration

 

Configuration>View and Edit>Edit

hierarchy.

 

Configuration.

 

2.

Next to System, click Configure or Edit.

 

3.

Next to Login, click Configure or Edit.

Create a user named remote who

1.

Next to User, click Add new entry.

belongs to the operator login class.

2.

In the User name box, type remote.

 

 

3.

In the Class box, type operator.

 

4.

Click OK.

CLI Configuration Editor

From the [edit] hierarchy level, enter

edit system login

Set the username and the login class for the user:

set user remote class operator

Managing User Authentication with a Configuration Editor 19

Page 41
Image 41
Juniper Networks J-Series manual Creating a Remote Template Account