Configure authentication and authorization settings
-
Remote Authentication Dial In User Service (RADIUS)
-
Terminal Access Controller Access-Control System (TACACS)
-
Lightweight Directory Access Protocol (LDAP)
Add a user group
To add a user group
-
On the Configuration tab, under System, expand User Administration, and then click Groups.
-
In the details pane, click Add.add-group
-
In the Create System Group page, set the following parameters:
-
Group Name
-
Group Description
-
System Access: Select this box to give access to the entire SDX appliance and the instances running on it. Alternatively, for instance-level access, specify the instances under Instances.
-
Permission
-
Configure User Session Timeout
-
Users: Database users belonging to the Group. Select the users you want to add to the group.
-
-
Click Create and Close.
Configure user accounts
To configure a user account
-
On the Configuration tab, under System, expand Administration, and then click Users. The Users pane displays a list of existing user accounts, with their permissions.
-
In the Users pane, do one of the following:
-
To create a user account, click Add.
-
To modify a user account, select the user, and then click Modify.
-
-
In the Create System User or Modify System User dialog box, set the following parameters:
-
Name*—The user name of the account. The following characters are allowed in the name: letters a through z and A through Z, numbers 0 through 9, period (.), space, and underscore (_). Maximum length: 128. You cannot change the name.
-
Password*—The password for logging on to the appliance. Maximum length: 128
-
Confirm Password*—The password.
-
Permission*—The user's privileges on the appliance. Possible values:
-
admin—The user can perform all administration tasks related to the Management Service.
-
read-only—The user can only monitor the system and change the password of the account. Default: admin.
-
-
Enable External Authentication—Enables external authentication for this user. Management Service attempts external authentication before database user authentication. If this parameter is disabled, the user is not authenticated with the external authentication server. Note: If the remote authentication server is not reachable, the user might lose access to the appliance. In such cases, authentication falls back to the default admin user (
nsroot). -
Configure Session Timeout—Enables you to configure the time period for how long a user can remain active. Specify the following details:
-
Session Timeout—The time period for how long a user session can remain active.
-
Session Timeout Unit—The timeout unit, in minutes or hours.
-
-
Groups—Assign the groups to the user.
*A required parameter -
-
Click Create or OK, and then click Close. The user that you created is listed in the Users pane.
To remove a user account
-
On the Configuration tab, in the navigation pane, expand System, expand Administration, and then click Users.
-
In the Users pane, select the user account, and then click Delete.
-
In the Confirm message box, click OK.
Set the authentication type
To set the authentication type
-
On the Configuration tab, under System, click Authentication.
-
In the details pane, click Authentication Configuration.
-
Set the following parameters:
-
Server Type—Type of authentication server configured for user authentication. Possible values: LDAP, RADIUS, TACACS, and Local.
-
Server Name—Name of the authentication server configured in the Management Service. The menu lists all the servers configured for the selected authentication type.
-
Enable fallback local authentication—Alternatively, you can choose to authenticate a user with the local authentication when external authentication fails. This option is enabled by default.
-
-
Click OK.
Enable or disable basic authentication
-
On the Configuration tab, click System.
-
In the System Settings group, click Change System Settings.
-
In the Configure System Settings dialog box, select Allow Basic Authentication to enable or clear Allow Basic Authentication to disable.
-
Click OK.