
RADIUS Overview
308640-15.1 Rev 00
1-7
SecurID, a token-passing security feature developed by Security Dynamics, Inc.,
prohibits unauthorized users from accessing a RADIUS client through a router
management application (Telnet, HTTP, FTP, or the Technician Interface). A
RADIUS client configured with SecurID communicates with a centrally located
ACE/Server to identify and authenticate authorized users.
SecurID offers a more advanced level of authentication because it requires two
security checks instead of one. To access the protected router, you must enter a
valid SecurID PASSCODE, which consists of:
• A secret, memorized personal identification number (PIN)
• The current token code, generated by your assigned SecurID card. The token
code appears in the liquid crystal display (LCD) of the SecurID card. The
code changes at a specified interval, typically 60 seconds.
The combination of the PIN and the token code ensures exceptionally secure user
authentication and access control.
Each user authorized to access a RADIUS client configured with SecurID must
have an electronic SecurID card issued by Security Dynamics, Inc. Security
Dynamics programs each card with a PIN to uniquely identify its prospective
owner, and then assigns the card for exclusive use to that person only.
Using RADIUS with Multilevel Access to the Router
System administrators and network operators can use RADIUS authentication
services from a console connected to the router. This feature, which is part of
Nortel Networks multilevel access, grants authenticated users access to the router
for configuration and monitoring purposes. Nortel Networks recommends that
you use the BCC to configure multilevel access.
Multilevel access also assigns a privilege level that determines which system
commands the user can execute. For more information, see Appendix A in Using
the Bay Command Console (BCC).
Comentarios a estos manuales