T.R | Title | User | Personal Name | Date | Lines |
---|
3446.1 | DNAS and DRAS = great solution | CSC32::R_BUCK | Authenticated and assimilated | Mon Feb 24 1997 16:06 | 8 |
| Take a look at the combination of DNAS V2.0 (or greater), and DRAS.
DRAS is the RADIUS security option. It allows a level of granularity
that would satisfy the stated needs. Web site www-ra.lkg.dec.com is a
great place to start for information and kits. Note file
IROCZ::NETRIDER tends to be the best place to discuss DNAS and DRAS.
Randall Buck
MCS - Network Support
|
3446.2 | | IROCZ::D_NELSON | Dave Nelson LKG1-3/A11 226-5358 | Mon Feb 24 1997 16:12 | 11 |
| RE: .0, .1
The authorization attributes you can specify for local UserAccounts on the
DECserver are a subset of those possible in RADIUS. AS Randall states in .1,
if the UserAccount feature in DNAS is not flexible enough, then use a
RADIUS server, like our DRAS product.
Regards,
Dave
|
3446.3 | | MUNICH::BLASCH | | Tue Feb 25 1997 10:08 | 11 |
| re .1, .2
Just to be sure I understood everything:
I can't derive the needed functionality by using only local security
of the Terminalserver.
I (or better the customer) need additional software like Radius.
Right?
Birgit
|
3446.4 | | IROCZ::D_NELSON | Dave Nelson LKG1-3/A11 226-5358 | Tue Feb 25 1997 10:23 | 34 |
| RE: .3
> Right?
Right.
The help screen for UserAccounts shows you what items can be associated with
a local user. Note that the name of a remote host is not available. It is
in RADIUS.
DEFINE/SET/CHANGE USERACCOUNT
Sets up a database for a user account for authentication and authorization.
{SET } USERACCOUNT name [ENABLE|DISABLE]
{DEFINE} [PASSWORD [quoted-string]]
{CHANGE} [[MAX] CONNECT {minutes|NONE}]
[ACCESS {FRAMED|LOCAL|LOGIN|NONE}]
[CALLBACK {ENABLE|DISABLE}]
[PERMISSIONS ({[DIALBACK|NODIALBACK]
[DIALOUT|NODIALOUT]
[LAT|NOLAT]
[TELNET|NOTELNET]
[SLIP|NOSLIP]
[PPP|NOPPP]
[PRIVILEGED|NOPRIVILEGED]})
[DIALOUT NUMBER {quoted-string|uppercase|ANY|NONE}]
[DIALOUT SERVICE {uppercase-name|NONE}]
[DIALBACK [NUMBER] {quotedstring|uppercase|ANY|NONE}]
Regards,
Dave
|