Security (RADIUS)

Provisioning RADIUS Security

Alert: To perform this procedure, the user must be logged on at the Security Admin security level.
Note 1: This section discusses both provisioning of RADIUS servers and Trusted Hosts. It is not necessary to provision RADIUS and enable Trusted Hosts. Conversely, it is not necessary to enable Trusted Hosts and provision RADIUS
Note 2: In addition to configuring RADIUS in the Panorama PON EMS, the RADIUS server must be properly provisioned to take advantage of the services provided by RADIUS (refer to the Tellabs 1100 Series Optical LAN Craft Interface User Interface Guide for additional details on RADIUS).

 

Remote Authentication Dial In User Service (RADIUS) security provisioning is available on an Optical Line Terminal (OLT) basis.

To provision RADIUS security.

  1. Logon to EMS and in the Network common tree, right-click on the target OLT and select Properties from the dropdown list and select the Security tab.

  2. In the Authentication Protocol Type, click the drop-down and select the desired Protocol Type. The protocol types are listed from least to most secure: None (default), PAPCHAP, and MSCHAPV2.

RADIUS Server for Craft Authentication

Attribute

Description

RADIUS Server Hostname/IP Address

Internet Protocol (IP) address of the RADIUS Server(s). IP addresses for up to four RADIUS Servers are supported.

Shared Key

Enter the shared security keyword.

Confirm Key

Re-enter the shared security keyword.

  1. In the RADIUS Server Hostname/IP Address field, enter the Internet Protocol (IP) address of the RADIUS Server.

  2. In the Shared Key field, enter the key information. Asterisks are displayed for the contents of the key fields.

  3. In the Confirm Key field, re-enter the information entered in the Shared Key field. Asterisks are displayed for the contents of the key fields.
Note: To view the Shared and Confirm Key fields, click on the view button.
  1. In the UDP Port field, enter the UDP Port number.
Note: The Set to Standards Button will reset the UDP port number from a nonstandard number to 1812 for RADIUS and to 3799 for DAC.

Trusted Host

Attribute

Description

Enable Trusted Host

Check box to enable trusted hosts.

IP Address

Address(es) of the trusted host servers to be recognized by this OLT. Up to 30 trusted host IP addresses can be listed.

  1. If Trusted Host is to be enabled, check the Enable Trusted Host check box. When Trusted Host is enabled, the OLT only allows TCP connection requests and SNMP requests to the management processes of this OLT from ONLY those IP addresses listed in the Host Table, plus any RADIUS or 802.1x servers that may be configured on this OLT. Enabling Trusted Host list does not affect user traffic.

  2. In the IP Address, enter the IP address(es) of the servers that the selected OLT must be able to communicate with. Up to 30 IP addresses can be added and can include, but is not limited to:

ICMP

Attribute

Description

Enable ICMP Destination Unreachable

Select ICMP Destination Unreachable to send a message in response to an undeliverable packet to its destination, due to reasons other than network congestion. Configured as packets per second. Default is Enabled.

Enable ICMP Group Echo Reply (ping)

Select ICMP Group Echo Reply to respond to a ICMP Ping. Enable ICMP Echo Reply controls whether the OLT will respond to ping messages. Default is Enabled.

ICMP Rate Limit

No Rate Limit

Slider button to the Left for No Rate Limit. 

Rate Limit (pkts/secs)

Slider button to the right to enable rate limit. Enter amount of packets in seconds.

  1. If ICMP is to be enabled, check the Enable ICMP Destination Unreachable check box. When ICMP Destination Unreachable is enabled, it generates a message in response to a packet undelivered to its destination.

  2. Check the Enable ICMP Group Echo Reply Ping check box. When ICMP Group Echo Reply Ping is enabled, it controls whether the OLT will respond to a ping message.
  3. Set the ICMP Rate Limit to No Rate Limit or Rate Limit as packets per second.
  4. After setting attributes in the Security tab, click the Save button.