Table of Contents

Authentication

The Authentication page can be accessed via the Authentication menu item by users with Administrator role.

Local Users

The Local Users tab allows administrators to add new users or edit existing users and their privilege levels. Depending on the selected role, the user has the following rights:

The minimum requirements for the passwords are as follows:


Add User window

TACACS+

The TACACS+ tab allows adding one or more TACACS+ servers, and configuring the following details:


Add TACACS+ Server window

RADIUS

The RADIUS tab allows adding one or more RADIUS servers, and configuring the following details:


Add RADIUS Server window

RADIUS privilege mapping values must use the data type defined for the corresponding RADIUS attribute. For example, attributes represented as integers/enumerated values, such as Service-Type, must be configured using the int type and their numeric value. Text-based attributes, such as Filter-Id, must be configured using the str type and their text value.

LDAP and LDAPS

The LDAP tab offers the possibility to configure one or more LDAP servers for user authentication. In order to set up the LDAP access, the following settings are required:


Add LDAP Server window

Custom authentication configuration

IOTA allows users to not only define multiple authentication methods, but also to configure how the different methods are used by the system. Clicking the Configure Authentication button on either the Users, TACACS+, RADIUS, or LDAP page allows users to see the list of available authentication methods and change their priority and activation strategy.

For each method, one of the following strategies can be selected:


Authentication Methods window