User Guide

Table Of Contents
Bridge GUI Guide: Security Configuration
143
NOTE:
When using
an external authen-
tication server, user and
(when applicable) device
authentication settings
are configured in the ex-
ternal application.
4.3.3 Local User and Device Authentication
You can configure user and device authentication settings even
when the Bridge’s local authentication is disabled (the default).
The settings will only be applied when the local RADIUS server
is enabled (refer to Section 4.3.2).
4.3.3.1 Local User Authentication Accounts
Locally authenticating users are displayed on the
User Entries
list on
Configure -> RADIUS Settings -> Local Server.
You cannot disable local user authentication, per se, except by
disabling local authentication entirely. There is, however, no
requirement that you configure local users.
The users for whom you create accounts can fall into one of
two categories:
Secure Client users - are running the Fortress Secure
Client on their connecting devices. They use the Bridge’s
local user authentication service to log on to the Bridge-
secured network. Secure Client users pass only encrypted
traffic on the Bridge’s encrypted interfaces.
Administrative users - use the Bridge’s local user
authentication service to log on to the management
interface of another Fortress Bridge on the network (or of
the local Bridge), when the administrative
Authentication
Method on that Bridge is set to RADIUS. Administrative
users pass only encrypted traffic on the Bridge’s encrypted
interfaces.
When an administrative user logs on to the Bridge through
a local or remote Fortress user authentication database (as
configured on the relevant
Local Server screen), a Learned
administrative account is created for that user in the
administrator authentication database. You can optionally
convert a
Learned account to a local administrative account
that can be used if the original user authentication service
becomes unavailable (refer to Section 2.2.2.8).
One can optionally convert the learned account(s) to local
account(s) that can be used when external admin auth is
disabled.
Default User Authentication Settings
While idle timeout and session timeout settings can be
individually configured for each user, the default values for
these settings are determined by the
Default Idle Timeout and
Default Session Timeout values configured on the local RADIUS
server (refer to Section 4.3.2).