Notes When Using Radius Authentication For Gui; Setting Up The Radius Server - Fujitsu Eternus web GUI User Manual

For eternus dx90 s2; eternus dx80 s2; eternus dx410 s2; eternus dx440 s2
Table of Contents

Advertisement

Appendix E Using RADIUS Authentication
E.2 Notes when Using RADIUS Authentication for GUI
E.2

Notes when Using RADIUS Authentication for GUI

A primary server and secondary server can be set for GUI authentication. If the primary
RADIUS server times out, the secondary server is tried.
If RADIUS Authentication fails and "Do not use Internal Authentication" has been selected for
"Authentication Error Recovery", it will not be possible to login to GUI or CLI.
When "Use Internal Authentication (Network Error Case)" has been selected for
"Authentication Error Recovery", Internal Authentication is only performed if RADIUS
Authentication fails on both primary and secondary RADIUS servers, and at least one of
these failures is due to network error.
So long as there is no RADIUS Authentication response the ETERNUS DX Disk storage
system will keep retrying to authenticate the user for the entire "Timeout" period set on the
"Set RADIUS Authentication (Initial)" menu. Authentication not succeeding before the timeout
occurs is considered a RADIUS Authentication failure.
When using RADIUS Authentication, if the role that is received from the server is unknown
(not set) for the device, RADIUS Authentication fails.
E.3

Setting Up the RADIUS Server

Windows Server 2008 R2 Example
The RADIUS setup procedure described below uses a Windows Server 2008 R2 as an example.
It must be noted that this setup procedure is not necessarily guaranteed to work for all network
environments. Make sure to obtain your system administrator's help in setting up the system.
The procedure for setting up the RADIUS service on Windows Server 2008 R2 is as follows.
(1) Install the Network Policy and Access Services
For details on installing "Network Policy and Access Services", refer to the Microsoft web-site.
(2) Enable the Challenge Handshake Authentication Protocol (CHAP)
If CHAP Authentication is required, set Windows to store passwords using reversible
encryption, rather than relying on the default setting.
If the current password is already stored by using irreversible
encryption, the current password setting is not changed even when
enabling the password to be stored by using reversible encryption. To
use reversible encryption to store the current password, set the user
password again or specify that the password for each user is changed
for the next login.
631
ETERNUS Web GUI User's Guide
Copyright 2011 FUJITSU LIMITED
P2X0-1090-02ENZ0

Advertisement

Table of Contents
loading

Table of Contents