Configuring User Authentication

RUCKUS ICX devices support role-based authentication. A device can perform authentication and authorization (role selection) using RADIUS and local configuration database. RUCKUS ICX devices also support multiple authentication methods for each service.

To implement one or more authentication methods for securing access to the device, you configure authentication-method lists that set the order in which the authentication methods are consulted.

In an authentication-method list, you specify the access method (RADIUS or Local) and the order in which the device tries one or more of the following authentication methods:

  • Local user authentication
  • RADIUS authentication

When a list is configured, the device attempts the first method listed to provide authentication. If that method is not available (for example, the device cannot reach a RADIUS server), the device tries the next method until a method in the list is available or all methods have been tried.

RUCKUS ICX devices allow multiple concurrent users through SSHv2 and the console. One user’s configuration changes can overwrite the changes of another user.

Local User Authentication

The local method of authentication uses a password associated with a user name to authenticate the user. A user enters a user name and corresponding password. The RUCKUS ICX device assigns the role associated with the user name to the user when authentication is successful.

To use local authentication, a Crypto-officer must define user accounts. The definition includes a user name, password, and privilege level (which determines the role).

RADIUS Authentication

The RADIUS method uses one or more RADIUS servers to verify user names and passwords. The RUCKUS ICX device prompts a user for a user name and password. The device sends the user name and password to the RADIUS server. Upon successful authentication, the RADIUS server returns the user’s privilege level, which determines the user’s role. If a RADIUS server does not respond, the RUCKUS ICX device sends the user name and password information to the next configured RADIUS server.

RUCKUS ICX devices support additional command authorization with RADIUS authentication. The following events occur when RADIUS command authorization takes place.

  1. A user previously authenticated by a RADIUS server enters a command on the RUCKUS ICX device.
  2. The RUCKUS ICX device looks at its configuration to see if the command is at a privilege level that requires RADIUS command authorization.
  3. If the command belongs to a privilege level that requires authorization, the RUCKUS ICX device looks at the list of commands returned to it when RADIUS server authenticated the user.

After RADIUS authentication takes place, the command list resides on the RUCKUS ICX device. The device does not consult the RADIUS server again once the user has been authenticated. This means that any changes made to the user’s command list on the RADIUS server are not reflected until the next time the RADIUS server authenticates the user and the server sends a new command list to the RUCKUS ICX device.

To use RADIUS authentication, a Crypto-officer must configure RADIUS server settings along with authentication and authorization settings.