User Guide

Table Of Contents
Bridge GUI Guide: Security Configuration
139
4.3.2.2 Local Authentication Server Port and Shared Key
The
Port setting configures the port to be used to communicate
with the local authentication server. The default authentication
server port is
1812, as assigned by the IANA (Internet
Assigned Numbers Authority) for RADIUS server
authentication.
Use the
New Shared Key and Confirm Shared Key fields to
establish the shared key for the Bridge’s internal authentication
server. The key must be 1–16 (inclusive) characters in length,
and it can contain any printable character. The same key must
be configured on other Fortress controller devices when they
are configured to use the current Bridge’s authentication
server.
4.3.2.3 Local Authentication Server Priority
In configurations with multiple authentication servers,
Priority
establishes the server’s position in the order of redundant
servers for the specified authentication type(s). Numerical
values between
1 and 999 are accepted. The default value,
Last, places the server last on the server priority list.
4.3.2.4 Local Authentication Server
Max Retries and Retry Interval
The
Max Server Retries setting determines the maximum
number of unsuccessful local authentication attempts a user or
device is allowed before being locked out. You can specify
whole numbers between
1 and 10; the default is 3.
A devices that exceeds the maximum allowable retry attempts
to authenticate on the Bridge is locked out until the device’s
individual
Auth State Mode is set to Allow First. Such a device is
locked out on every Bridge in a network, and you must change
the device’s
Auth State Mode on every Bridge that handles
traffic from the device.
Users who exceed the maximum allowable retry attempts to
log on to the Bridge-secured network are locked out until you
reset their sessions. On a network of Bridges, you must reset
the session on each Bridge that passes traffic for the device.
Retry Interval specifies how long the Bridge requires a user or
device to wait between connection retries.
4.3.2.5 Local Authentication Server
Default Idle and Session Timeouts
The
Default Idle Timeout setting determines the amount of time
a device can be idle on the network before the current session
is ended and the associated Device ID and/or user credentials
must be reauthenticated and keys renegotiated before the
connection can be re-established. If local user authentication is
in effect for the device and
Permit cached authentication
credentials is globally Disabled on Configuration -> Security