Contents

User's Guide
Overview
What It Is
What's New
Key Features List
ClearBox Enterprise vs ClearBox
System Requirements
Purchasing Licenses
Getting Started
Quick Start
Understanding Server Components
Managing User Accounts
Configuring RADIUS Realms
Realm Settings
Realm Rules
Dynamic Realm Rules
Authentication
Authentication Protocols Compatibility
Logging Authentication Packets
Logging Discarded Requests
Authorization
Accounting
Account Log Files
Realm Settings
Configuring SQL Queries
Private RADIUS Attributes
Regular Expressions Syntax
RADIUS Clients
RADIUS Client Settings
Dynamic Clients Settings
SQL Data Sources
SQL Data Source Settings
LDAP Servers
LDAP Server Settings
Remote RADIUS Servers
Remote RADIUS Server Settings
State Servers
State Server Settings
Meta Configuration
Meta Configuration
Meta Configuration Settings
Meta Base Schema
TLS Settings
Creating SSL Certificates
Creating Server Sertificate
Requesting Server Certificate
Creating Client Certificates
Revoking a Certificate or Renewing CRL
Exporting CA Certificate
Issuing a Certificate in Active Directory CA
Remote Configuration
Advanced ISP Billing Integration
DTH Billing Integration
Platypus Billing System Intergration
OnDO SIP Server Integration
How Do I...
Wi-Fi Security
Wireless Authentication
Wi-Fi and RADIUS
Supported EAP Authentication Types
Security Considerations
10 Tips for Wireless Network Security
Administering the Server
Logging
Debug Logs
Troubleshooting
Using Client Tool
List of Server Errors
Maintaining RADIUS Dictionary
Basic Concepts
AAA
Authentication
Wireless Authentication
Authentication Protocols
Authorization
Accounting
RADIUS
RADIUS
Realms
RADIUS Proxy
RADIUS Attributes
Example of RADIUS Packet Transactions
List of Standard RADIUS Attributes
Glossary
Technical Support
Purchasing Licenses
Contacts

 
Home
ClearBox Enterprise Server 2.0 Online Manual
Prev Page Next Page
 
 
ClearBox Enterprise Serverâ„¢ 2.0. User's Guide

Realm Authentication Settings

Each realm has its independent authentication settings. They define how a user should be authenticated.

Ignore user name and password. Check this option on to skip user authentication.

Maximum number of concurrent session. Setting this value to a number larger than 0 makes ClearBox server check that sessions established by a user does not exceeds this threshold. This value applies for every user authenticated within this realm. Valid State server ID should be selected. If the number is zero, no check is performed at the realm level.

State server ID. Select a configured state server from the list to specify where ClearBox should take the information about concurrent user sessions.

Select new realm by inner user identity (for PEAP authentication). In PEAP wireless authentication, a supplicant may send fake user name in so-called 'outer' clear text phase and send real user name only during secure SSL-encrypted so-called 'inner' authentication phase. Set this option, if another realm should be selected by this real user name sent through the inner secure channel. Note, that there should be configured some realm with By fully qualified user name rule activated and Use this rule only for wireless PEAP inner authentication option set.

Expand Allowed Authentication Protocols.

Click the button to configure what authentication protocols supported by ClearBox server are allowed in this realm. This is very important for wireless authentication, as only mutually compatible types should be chosen.

Available authentication databases:

Expand Remote RADIUS servers.

Select this authentication method to turn ClearBox into a RADIUS proxy server and make it forward authentication requests to another remote RADIUS server.

Expand Windows NT/2000 domain or workgroup .

Select it if you have your users account already stored in a Windows domain, workstation or Windows Active Directory. ClearBox can authenticate users against Windows domains, groups, workstations.

Expand SQL database.

Choose this option to authenticate users against an external relational SQL-compliant database. ClearBox can use any existing database structure, so no database redesign is needed.

Expand Generic LDAP server.

Choose this option to authenticate users against an LDAP-compliant directory.

Click 'Apply Changes' when you have configured realm authentication settings and want to save them.


© 2001-2007 XPerience Technologies. www.xperiencetech.com
Converted from CHM to HTML with chm2web Pro 2.7 (unicode)