[HOWTO] Authenticating Omnivista user via radius
Posted: 26 Apr 2012 11:43
Hi,
A little feedback on the Omnivista 2500 user authentication configuration with radius.
Tested with Omnivista 2500 version 3.5.3 GA 64 bits with WebServices and two NPS servers Microsoft 2008 R2.
Alcatel documentation : https://service.esd.alcatel-lucent.com/ ... umber=7254
Some docs in the Omnivista Help but not really helpful.
You need a working Omnivista 2500 server and one working NPS server.
1 )Connect to your NPS server and create a new radius client witch is your Omnivista2500 server. (write down the shared secret
)
2 )Create a new Network policy with a User Groups condition (Active Directory User Group)
3 )In the parameters tab, add a Vendor Specific attribute with this configuration :
Vendor Code : 800 and configure attribute
Vendor-assigned attribute number : 20 <Alcatel-Nms-Group>
Attribute format : String
Attribute value : Default <This parameters return the Omnivista Group, Case Sensitive !>
The Default Omnivista group has Read-Only rights, if you need Read-Write, the Attribute value is : Administrators <Case Sensitive too !>
4 ) Valid all windows and login your Omnivista 2500 server and open Omnivista2500 software
5 ) Go to “Security”, “Authentication Servers”, click on the “Radius” tab and create a new radius server witch is your NPS server (take your paper with the shared secret)
6 ) Go to “Security”, “Users and User Group”, check that the group Default or Administrators is existing
7 ) Click “Authentication Server” and select the radius server object created in step 5
8 ) Apply.
9 ) Test the radius user authentication FROM ANOTHER INSTANCE of Omnivista !!< yes you can run multiple client instances on the same PC/server>
WARNING : Don’t close your first Omnivista 2500 instance before you have fully tested that the radius authentication is working !! Otherwise you will need to shutdown the NPS service on the radius server, because Omnivista 2500 don’t try to authenticate user with the local database if a radius server is configured and running.
Now you may be able to login Omnivista with your Active Directory account.
It's also working for Omnivista Web Services !!
See below the full Radius attribute list for Alcatel-NMS:
ATTRIBUTE Alcatel-Nms-Group Alcatel-Attr(20, string) R
ATTRIBUTE Alcatel-Nms-First-Name Alcatel-Attr(21, string) r
ATTRIBUTE Alcatel-Nms-Last-Name Alcatel-Attr(22, string) r
ATTRIBUTE Alcatel-Nms-Description Alcatel-Attr(23, string) r
A little feedback on the Omnivista 2500 user authentication configuration with radius.
Tested with Omnivista 2500 version 3.5.3 GA 64 bits with WebServices and two NPS servers Microsoft 2008 R2.
Alcatel documentation : https://service.esd.alcatel-lucent.com/ ... umber=7254
Some docs in the Omnivista Help but not really helpful.
You need a working Omnivista 2500 server and one working NPS server.
1 )Connect to your NPS server and create a new radius client witch is your Omnivista2500 server. (write down the shared secret
2 )Create a new Network policy with a User Groups condition (Active Directory User Group)
3 )In the parameters tab, add a Vendor Specific attribute with this configuration :
Vendor Code : 800 and configure attribute
Vendor-assigned attribute number : 20 <Alcatel-Nms-Group>
Attribute format : String
Attribute value : Default <This parameters return the Omnivista Group, Case Sensitive !>
The Default Omnivista group has Read-Only rights, if you need Read-Write, the Attribute value is : Administrators <Case Sensitive too !>
4 ) Valid all windows and login your Omnivista 2500 server and open Omnivista2500 software
5 ) Go to “Security”, “Authentication Servers”, click on the “Radius” tab and create a new radius server witch is your NPS server (take your paper with the shared secret)
6 ) Go to “Security”, “Users and User Group”, check that the group Default or Administrators is existing
7 ) Click “Authentication Server” and select the radius server object created in step 5
8 ) Apply.
9 ) Test the radius user authentication FROM ANOTHER INSTANCE of Omnivista !!< yes you can run multiple client instances on the same PC/server>
WARNING : Don’t close your first Omnivista 2500 instance before you have fully tested that the radius authentication is working !! Otherwise you will need to shutdown the NPS service on the radius server, because Omnivista 2500 don’t try to authenticate user with the local database if a radius server is configured and running.
Now you may be able to login Omnivista with your Active Directory account.
It's also working for Omnivista Web Services !!
See below the full Radius attribute list for Alcatel-NMS:
ATTRIBUTE Alcatel-Nms-Group Alcatel-Attr(20, string) R
ATTRIBUTE Alcatel-Nms-First-Name Alcatel-Attr(21, string) r
ATTRIBUTE Alcatel-Nms-Last-Name Alcatel-Attr(22, string) r
ATTRIBUTE Alcatel-Nms-Description Alcatel-Attr(23, string) r