Configuring User Authentication

RUCKUS FastIron devices support role-based authentication. A device can perform authentication and authorization (role selection) using RADIUS and local configuration database. FastIron devices also support multiple authentication methods for each service.

To implement one or more authentication methods for securing access to the device, you configure authentication-method lists that set the order in which the authentication methods are consulted.

In an authentication-method list, you specify the access method (SSHv2, SNMP, and so on) and the order in which the device tries one or more of the following authentication methods:

  • Local user authentication
  • RADIUS authentication

When a list is configured, the device attempts the first method listed to provide authentication. If that method is not available (for example, the device cannot reach a RADIUS server), the device tries the next method until a method in the list is available or all methods have been tried.

FastIron devices allow multiple concurrent operators through SSHv2 and the console. One operator’s configuration changes can overwrite the changes of another operator.

Local User Authentication

The local method of authentication uses a password associated with a user name to authenticate an operator. An operator enters a user name and corresponding password. The FastIron device assigns the role associated with the user name to the operator when authentication is successful.

To use local authentication, a Crypto-officer must define user accounts. The definition includes a user name, password, and privilege level (which determines the role).

RADIUS Authentication

The RADIUS method uses one or more RADIUS servers to verify user names and passwords. The FastIron device prompts an operator for user name and password. The device sends the user name and password to the RADIUS server. Upon successful authentication, the RADIUS server returns the operator’s privilege level, which determines the operator’s role. If a RADIUS server does not respond, the FastIron device sends the user name and password information to the next configured RADIUS server.

FastIron series devices support additional command authorization with RADIUS authentication. The following events occur when RADIUS command authorization takes place.

  1. A user previously authenticated by a RADIUS server enters a command on the FastIron device.
  2. The FastIron device looks at its configuration to see if the command is at a privilege level that requires RADIUS command authorization.
  3. If the command belongs to a privilege level that requires authorization, the FastIron device looks at the list of commands returned to it when RADIUS server authenticated the user.

After RADIUS authentication takes place, the command list resides on the FastIron device. The device does not consult the RADIUS server again once the operator has been authenticated. This means that any changes made to the operator’s command list on the RADIUS server are not reflected until the next time the RADIUS server authenticates the operator, and the server sends a new command list to the FastIron device.

Note: Radius over TLS is supported in FIPS mode.

To use RADIUS authentication, a Crypto-officer must configure RADIUS server settings along with authentication and authorization settings.