User Guide

Table Of Contents
Bridge GUI Guide: Security Configuration
136
relevant server and failed credentials are not forwarded to any
other server.
If the server with first priority for a given authentication type
becomes unavailable, the next server in the priority sequence
that has also been configured to support that authentication
type will be used.
In Advanced View, where you can configure up to four RADIUS
servers, you can specify the priority number of each. In Simple
View,
RADIUS Server 1 has priority over RADIUS Server 2.
Advanced View also allows you to configure the maximum
number of allowable authentication attempts and the retry
interval for each server. These settings apply globally to all
users and (if applicable) devices authenticated by that server.
4.3.1 Authentication Server Settings
External authentication servers can be added and reconfigured
only through the settings described below.
Once the internal authentication server has been added to the
Bridge configuration with the settings on the
Local Server tab of
the
RADIUS Settings screen, you can reconfigure some
aspects of its operation from its entry on the
Server List or, in
Simple View, in the corresponding
RADIUS Server frame.
However, the internal server can be added, and complete
settings for it can be accessed, only on the
Local Server tab, as
described in Section 4.3.2.
4.3.1.1 Authentication Server State, Name, and IP Address
NOTE: The Server
Name
and IP Ad-
dress
of the internal RA-
DIUS server (
Local Auth
Sever
and 127.0.0.1, re-
spectively) are internal-
ly set and cannot be
changed.
The Admin State setting determines whether the Bridge
forwards authentication requests of the applicable type(s) to
the server (
Enabled) or not (Disabled).
You must specify a unique
Server Name to identify an external
server in the Bridge configuration. You cannot edit the
Server
Name once it is established.
You must specify the network
IP Address of an external
authentication server in order to add it to the Bridge
configuration.
4.3.1.2 Authentication Server Port and Shared Key
The
Port setting configures the UDP port to be used to
communicate with the authentication server. The default
authentication server port is
1812, as assigned by the IANA
(Internet Assigned Numbers Authority) for RADIUS server
authentication.
NOTE: The server
key you enter here
should already be pres-
ent in the authentication
service configuration.
Use the New Shared Key and Confirm Shared Key fields to
establish the key used to authenticate the Bridge on the
external authentication server.