TMS zl Management and Configuration Guide ST.1.1.100226
4-68
Firewall
User Authentication
Table 4-10. RADIUS Attributes Required for RADIUS Access-Accept Messages
Example RADIUS Configurations
This section includes some example configurations for two RADIUS servers
that work with the TMS zl Module:
■ “Windows IAS” on page 4-68
■ “Windows NPS” on page 4-77
Windows IAS. This example shows the step-by-step configuration that
allows the TMS zl Module to coordinate with Microsoft Internet Authentica-
tion Service (IAS) to authenticate users.
This example requires you to have the following:
■ A Windows Server 2003 functioning at the Windows 2000 level, or higher.
■ IAS installed on that server.
■ Users and user groups configured in Active Directory.
For more information, see http://www.microsoft.com.
1. Open IAS on your Windows server by clicking Start > Administrative Tools
> Internet Authentication Service. The Internet Authentication Service win-
dow is displayed.
2. Click Action > Register Server.
3. Click OK.
Attribute Value Additional Guidelines
Service-Type Not defined or any value
except:
• Administrative-User
• NAS-Prompt
•Framed
Those three values are reserved for other types
of users.
Filter-ID Name of a user group on the TMS zl Module The value must match exactly a name that you
configured in “Create User Groups” on page
4-65. When a user authenticates with this policy,
the firewall access policies configured for this
group on the module will control the user’s
access.