User guide

Chapter 5: Users, Groups, and Access Permissions
61
Remote Authentication
Note to CC-SG Users
WhentheKXII101iscontrolledbyCommandCenterSecureGateway,
CCSGauthenticatesusersandgroups,exceptforlocalusers(requiring
localportaccess).WhenCCSGiscontrollingtheKXII101,localport
userswillbeauthenticatedagainstthelocaluserdatabaseortheRemote
Authenticationserver(LDAP/LDAPSorRADIUS)co
nfiguredontheKX
II101;theywillnotbeauthenticatedagainsttheCCSGuserdatabase.
ForadditionalinformationaboutCCSGauthentication,refertothe
CommandCenterSecureGatewayUserGuide,AdministratorGuide,or
DeploymentGuideat:
http://www.raritan.com/support/productdocumentation.
Supported Protocols
Inordertosimplifymanagementofusernamesandpasswords,theKX
II101providesthecapabilitytoforwardauthenticationrequeststoan
externalauthenticationserver.Twoexternalauthenticationprotocolsare
supported:LDAP/LDAPSandRADIUS.
Note on Microsoft Active Directory
MicrosoftActiveDirectoryusestheLDAP/LDAPSprotocolnatively,and
canfunctionasanLDAP/LDAPSserverandauthenticationsourcefor
KXII101.IfithastheIAS(InternetAuthorizationServer)component,a
MicrosoftActiveDirectoryservercanalsoserveasaRADIUS
authenticationsource.
Authentication vs. Authorization
Authenticationistheprocessofverifyingthatauseriswhohesaysheis.
Onceauserisauthenticated,theuserʹsgroupisusedtodeterminehis
systemandportpermissions.Theuserʹsassignedprivilegesdetermine
whattypeofaccessisallowed.Thisiscalledauthorization.
WhenKXII10
1isconfiguredforremoteauthentication,theexternal
authenticationserverisusedprimarilyforthepurposesof
authentication,notauthorization.