Protected user authentication
To configure protected user authentication by using the CLI
add authentication protectedUserAction protectedUser -realmStr <AAA.LOCAL> -maxConcurrentUsers <8>
-
realmStr: Specifies the domain to which the user belongs. This parameter is mandatory. -
maxConcurrentUsers: Limits the number of concurrent authentication requests to prevent DDoS attacks. This parameter is optional. Default value: 8.
aaa.local1, then that realm must be mentioned as part of realmStr parameter as follows:
add authentication protectedUserAction <name> -realmStr aaa.local1
To configure protected user authentication by using the GUI
-
Configure the LDAP group extraction to extract the users in the “Protected Users” group. For more information, see Create an LDAP Authentication Action using the GUI.
-
Navigate to Security > AAA - Application Traffic > Policies > Authentication > Advanced Policies > Actions > PROTECTED USER and click Add.
-
In the Protected User Actions page, enter values for the following parameters:
-
Name: Name for the protected user authentication. This parameter is mandatory.
-
Kerberos Realm: Domain to which the user belongs. This parameter is mandatory.
-
Max Concurrent Users: Limits the number of concurrent authentication requests to prevent DDoS attacks. This parameter is optional. Default value: 8.
-
-
Click Create.