Chapter 6 Configuring authentication 277

2Modify settings for the RADIUS configuration as necessary. Table 42 describes the Radius Configuration fields.

Table 42 Radius Configuration fields

Field

Description

 

 

Vendor Id for Group

Specifies the vendor-specific attribute used by the RADIUS

Attributes

server to send group names to the Nortel SNAS 4050. The

 

default Vendor-Id is 1872 (Alteon).

 

To use a standard RADIUS attribute rather than the

 

vendor-specific one, set the vendor ID to 0 (see also

 

vendor type).

 

Note: If the Authentication Protocol is CHAPv2, the

 

Vendor-Id must be set to 311 (Microsoft).

 

 

Vendor Type for Group

Specifies the Vendor-Type value used in combination with

Attributes

the Vendor-Id to identify the groups to which the user

 

belongs. The group names to which the vendor-specific

 

attribute points must match names you define on the Nortel

 

SNAS 4050. The default is 1.

 

If you set the vendor ID to 0 in order to use a standard

 

RADIUS attribute (see vendor ID), set the vendor type to a

 

standard attribute type as defined in RFC 2865. For

 

example, to use the standard attribute Class, set the

 

vendor ID to 0 and the vendor type to 25.

 

 

Vendor Id for Domain ID

Specifies the vendor-specific attribute used by the RADIUS

Attributes

server to send domain names to the Nortel SNAS 4050.

 

The default Vendor-Id is 1872 (Alteon).

 

Note: If the Authentication Protocol is CHAPv2, consider

 

setting the Vendor-Id for the domain to 10

 

(MS-CHAP-Domain).

 

 

Vendor Type for Domain ID

Specifies the Vendor-Type value used in combination with

Attributes

the Vendor-Id to identify the domain. The default is 2.

 

 

Radius Server Timeout

Sets the timeout interval for a connection request to a

 

RADIUS server. At the end of the timeout period, if no

 

connection has been established, authentication will fail.

 

Acceptable values are an integer that indicates the time

 

interval followed by a letter to specify the measurement

 

unit. The options for measurement units are:

 

s — seconds

 

m — minutes

 

h — hours

 

If you do not specify a measurement unit, seconds is

 

assumed. The range is 1–10000 seconds. The default is

 

10 seconds.

 

 

 

Nortel Secure Network Access Switch 4050 User Guide

Page 277
Image 277
Nortel Networks 4050 manual Radius Configuration fields