Hello all,
I have setup Observium with radius auth.
Today I noticed that everyone is getting full admin rights in Observium.
I changed my own radius settings and tested.
Observium is running on 10.230.11.81 and radius on 10.230.11.111
This is the radius response:
(587) Sent Access-Accept Id 94 from 10.230.11.111:1812 to 10.230.11.81:43443 length 0
(587) Juniper-Local-User-Name = "remote"
(587) Filter-Id = "pfy"
ß
(587) GENIE-USER-PRIVILEGE = PRIV-ADMINISTRATOR
(587) Infinera-User-Category = "administrator"
(587) Service-Type = Administrative-User
(587) NS-Admin-Privilege = All-VSYS-Root-Admin
(587) Class = 0x6e65
Config.php:
$config['auth_radius_groups']['admin']['level'] = 10; // Full administrative access
$config['auth_radius_groups']['cto']['level'] = 7; // Global read access with secured info (ie rancid configs)
$config['auth_radius_groups']['pfy']['level'] = 5; // Global read access
Any idea what I’m doing wrong?
Met vriendelijke groet,
Peter Derissen
Eurofiber Nederland
Network Engineer Safariweg 25-31
+31 (0)6 11587110 3605 MA Maarssen
Volg ons op Twitter
| Linkedin |
Facebook |
Youtube
Wilt u op de hoogte blijven van technische ontwikkelingen aan ons netwerk, nieuwe ICT ontwikkelingen en klantervaringen? Meld u dan aan
voor onze maandelijkse nieuwsbrief.