For an introduction to RADIUS authentication in SonicOS, see Using RADIUS for Authentication. If you selected RADIUS or RADIUS + Local Users from the Authentication method for login drop-down menu on the Users > Settings page, the Configure button becomes available.
A separate Configure button for RADIUS is also available if you selected Browser NTLM authentication only from the Single-sign-on method drop-down menu, or in various cases where configuration elsewhere may require that RADIUS be used. The configuration process is the same.
The following points describe the selection of authentication methods when using RADIUS:
•
|
With VPN including Global VPN Client, RADIUS MSCHAP/MSCHAPv2 mode can be forced to allow password updating. This can be selected in the VPN > Advanced page and the SSL VPN > Server Settings page.
|
•
|
The Allow HTTP login with RADIUS CHAP mode option on the Users > Settings page allows users to log in via HTTP rather than HTTPS when using RADIUS to authenticate them. CHAP mode provides a challenge protocol for authentication so that the browser does not send the user’s password in the clear over HTTP.
|