Owners manual
30
2. Web Configuration Interface
Access Rights Permission String – In order for access rights to be assigned in User or Group authentication mode, a permission string
must be entered into the directory attribute that is assigned to each User or Group. The name of this attribute must be entered into the
Access Rights Attribute field in the Mode section of the Authentication page. See below for an explanation of how the permission string
needs to be formatted.
Access Category – An Access Category is an entry in the permission string that refers to a particular access right to the KVM switch. The
available Access Categories are listed below.
Note:
1. Access Categories are case sensitive.
2. Access rights must be assigned for each Access Category, regardless of whether User or Admin is assigned as the kvmrole.
• kvmdevice – ReferstotheDeviceNameofaNetCommanderIPMulti-UserKVMswitch.TheDeviceNameofaKVMcanbefound
in the Device tab of the Configuration section of the web configuration interface (See the Device section in this manual for details). If
kvmdevice is not referenced in the permission string, then access will be allowed to all KVM switches.
• kvmrole –Referstothetypeofaccount,andcanbeeitherAdmin or User (See the Users section of this manual for details on these
account types).
• kvmports –Referstothelistofportsthatanaccountisallowedtoaccess.Portsareseparatedinthepermissionstringbyacomma.
An asterisk (*) can be used to indicate access to all ports.
• vm_ports –Referstothelistofvirtualmediaportsthatanaccountisallowedtoaccess.Portsareseparatedinthepermissionstringby
a comma. An asterisk (*) can be used to indicate access to all ports.
• kvmtelports –Referstothelistofserialportsthatanaccountisallowedtoaccess.Portsareseparatedinthepermissionstringbya
comma. An asterisk (*) can be used to indicate access to all ports.
Sample Permission String
kvmdevice:D1144567,kvmrole:user,kvmports:1,2,5,vm_ports:1,2,kvmtelports:*
The permission string above assigns a User or GroupwithaccesstotheKVMwithDeviceNameD1144567.TheaccountisgivenUser
permissionsandhasaccesstoports1,2,and5ontheKVM,canaccessvirtualmediaonports1and2,andcanaccessallserialports.
RADIUS Authentication Settings – Once enabled in the Enabled Authentications Methodssection,RADIUSauthenticationissetupusing
the fields in the Authentication Sourcessection.TosetupRADIUSauthentication,makesurethattheRADIUS tab in the Authentication
Sources section is selected, and then follow the instructions below. Note: For RADIUS Authentication to work properly, a Tripp Lite dictionary
must be installed on the RADIUS server. The dictionary should be present in the latest dictionaries supplied by FreeRADIUS, or can be
manually downloaded at www.tripplite.com/support.
Servers – At the bottom of the page, the ServerssectionallowsyoutoaddRADIUSserverstotheKVM.Aswiththeauthenticationmethods
in the Enabled Authentication Methodssectionatthetopofthepage,RADIUSserverscanbelistedaccordingtopriority.Therstserver
in the list will be the first one accessed by the KVM during authentication, followed by the second server, etc. To avoid performance issues
duringtheauthenticationprocess,itisrecommendedthatyouaddnomorethanthreeRADIUSservers.
•ToaddaRADIUSservertothelist,clickontheAdd button to bring up the Add RADIUS Server screen.
•EntertheIPv4, IPv6, or Host addressforyourRADIUSserverinthecorrespondingeld.
Note: The Host name should only be used for IPv4 RADIUS servers. For IPv6 RADIUS servers, the IPv6 address should be used instead of
a Host name.
•SelecttheauthenticationPort number and Accounting Port number to be assigned to the server. The default authentication port number is
1812,andthedefaultaccountingportnumberis1813.
14-03-053 93-3261.indd 30 3/14/2014 1:38:06 PM