Zyxel ZyWALL USG 20 [169/185] Zywall usg support notes

Zyxel ZyWALL USG 50 [169/185] Zywall usg support notes
ZyWALL USG Support Notes
169
All contents copyright (c) 2010 ZyXEL Communications Corporation.
control and also a basis for user-aware device. A user-aware device like ZyWALL
USG could use authentication method to authenticate a user (to prove who the user is)
and give the user proper authority (defining what the user is allowed and not allowed
to do) by authorization method. Accounting measures the resources a user consume
during access which is used for authorization control, resources utilization and
capacity planning activities.
AAA services are often provided by a dedicated AAA server or a local database in a
user-aware device. The most common server interfaces are LDAP and RADIUS.
In ZyWALL USG, AAA object allows administrators to define the local database,
AAA server(including LDAP server and RADIUS server) and related parameters.
AAA groups are ones that could group several AAA servers for those enterprises that
have more than one AAA server. Furthermore, if the three kinds of services, LDAP,
RADIUS and Local exist at the same time, administrators could decide the order of
different AAA services by AAA method.
M06. What are ldap-users and radius-users used for?
ldap-users/radius-users refer to the users that are authenticated successfully via
LDAP/RADIUS server. If you want to perform access control rules or build access
policies for the users authenticated via external servers such as LDAP or RADIUS,
you can use the ldap-users and radius-users in your access control rules or policies.
M07. What privileges will be given for ldap-users and
radius-users?
When a user has been authenticated by external database (ladp or radius server), it
will retrieve the users attributes (like lease timeout and re-auth timeout value) from
the external server. If the external server doesn‟t define the users attributes, it will try
to check local database on ZyWALL USG (at GUI menu Configuration >
User/Group > User tab or Group tab) instead. If it still cannot find, it will use the
attribute of “ldap-users” and “radius-users” at GUI menu Configuration >
User/Group > User tab as below. The default lease time and re-authentication time of
ldap-users and radius-users are 1440 minutes.

Содержание

Похожие устройства

Скачать