Forum Discussion
Radius Authentication
I've only done this with tacacs+ and a Cisco ACS server, but I think the general idea is about the same, and is hopefully helpful.
First, you need to create remote roles on the F5 for each role you want to create. When you create the role, you designated what F5 role they get(admin, guest and so on), and to what partition they have access to. You also need to fill in the Attribute String, which is the radius attribute you are going to use designate a user gets this role. For me, I use:
F5-LTM-User-Info-1=role-name in the Attribute String field, where role-name is just a string that identifies this role.
After that you will need to import the F5 vendor-specific attributes into your radius server, and then send the F5-LTM-User-Info-1 attribute with the value of role-name for each user.
When the login requests comes through, the F5 will see the F5-LTM-User-Info-1 attribute and map them to the proper remote role group, which defines the partition access.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com