Radius - Read only login

DOWNLOAD THE LATEST FIRMWARE HERE
jfrawley
Member
 
Posts: 2
Joined: Wed Apr 06, 2016 8:51 pm
Has thanked: 0 time
Been thanked: 0 time

Radius - Read only login

Thu Jun 27, 2019 5:57 am

Would really like to add a read only user account to my switches for techs who do not need to make changes but simply check voltage or port status.

In conjunction I found with radius (we use pppoe for our clients fyi) that if I enable it then any of the usernames and passwords in my radius db will auth and give full access to the switch :( scary

Anything coming in near future for at least a read only user account? Please and thank you!

Jason

User avatar
Stephen
Employee
Employee
 
Posts: 1033
Joined: Sun Dec 24, 2017 8:56 pm
Has thanked: 85 times
Been thanked: 181 times

Re: Radius - Read only login

Thu Jun 27, 2019 12:43 pm

I will have to investigate how we would do something like this. In the mean time, you should be able to get this information from snmp so could you have your technician's use an snmp based tool to monitor these value's?

User avatar
mike99
Associate
Associate
 
Posts: 837
Joined: Tue Nov 25, 2014 10:53 am
Location: Quebec, Canada
Has thanked: 95 times
Been thanked: 245 times

Re: Radius - Read only login

Fri Jun 28, 2019 7:19 am

https://freeradius.org/rfc/rfc5607.html ... lege-Level

Privilege Level is vendor specific. I think he would like privilege level (0) to be without any access since, if I understand well, he share the same radius server for customers authentification and employees authentification. That don't seem best practice.

From this forum, Cisco privilage level 0 give accces to disable, enable, exit, help, and logout commands. That's not much but still an access I would not like my customer to have with their PPPoE username and password.
https://community.cisco.com/t5/policy-a ... -p/1087452

Return to Hardware and software issues

Who is online

Users browsing this forum: Google [Bot] and 49 guests