Manual Chapter :
RADIUS User Authentication
Applies To:
Show VersionsBIG-IQ Centralized Management
- 8.3.0, 8.2.0, 8.1.0
RADIUS User Authentication
Use my RADIUS server to authenticate BIG-IQ users
F5 BIG-IQ Centralized Management can verify user credentials against your company's RADIUS server. After you set up BIG-IQ to use your RADIUS server, you can add users and user groups authorized by that server.
Before integrating
BIG-IQ with your RADIUS server for authentication and authorization
Before you set up BIG-IQ Centralized Management for
authentication and authorization with your RADIUS server, gather the following
information.
Required Information | This is |
---|---|
Name | The name of your RADIUS server. |
Host | The IP address or host name of your RADIUS server. |
Port | The port number of your RADIUS server. |
Secret | The case-sensitive text string used to validate
communication. |
Test user name and password | A user name and password, authenticated on your RADIUS
server. |
Key and Value properties for your RADIUS server | The RADIUS server uses this for authentication and
encryption. |
Set up BIG-IQ to use my RADIUS server for user
authentication
Before you can set up
authentication, you must have specified your DNS settings. You usually do this when you
license F5 BIG-IQ Centralized Management.
You can set up BIG-IQ to use
your company's RADIUS server. You can add two additional backup RADIUS servers in
case the primary server is not available for authentication.
- At the top of the screen, clickSystem.
- On the left, click.
- Click theAddbutton.
- From theProvider Typelist, selectRADIUS.
- In theNamefield, type a name for this new provider.This must be a unique name, and can be a maximum of 152 characters.
- For theServerssetting, In theHostandPortfields, type the RADIUS server's IP address (or fully qualified domain name) and port number for each of the servers you want to configure.The primary server is mandatory. A secondary server and tertiary server, which will be used if the primary or secondary servers fail, are optional.
- In theSecretfield, type the case-sensitive text string used to validate communication.
- In theTest UserandTest Passwordfields, type a user and password, then click theTestbutton to verify that BIG-IQ can reach the RADIUS server
- Click theSave & Closebutton at the bottom of the screen.
You can now associate RADIUS server users and
groups with BIG-IQ system roles.
Add a user authenticated by my RADIUS server and associate it with a role
If you want to add a user authenticated against your RADIUS server, you first have to set up F5 BIG-IQ Centralized Management with your RADIUS server settings.
Once you understand exactly who you want to perform certain tasks,
you can provide them access to particular areas of BIG-IQ by adding them as a user and
assigning the appropriate built-in or custom role. You can assign as many roles as
required to cover the user's responsibilities.
For the RADIUS-authenticated user to access BIG-IQ, you must put the
local user in a BIG-IQ role, or put in a role a local group mapped to one of the user’s
groups on the RADIUS server.
- At the top of the screen, clickSystem.
- On the left, click.
- Click theAddbutton.
- From theAuth Providerlist, selectRADIUS.
- In theUser Namefield, type the name for this user.
- In theFull Namefield, type a name to identify the individual with this type of user access.The full name can contain a combination of letters, symbols, numbers and spaces.
- For theRolessetting, from theAvailablelist, select each user role you want to associate with this user, and move it to theSelectedlist.Be sure to let your users know that their access to certain parts of the BIG-IQ user interface depends on which role they are assigned.
- Click theSave & Closebutton.
If this BIG-IQ is part of an HA pair, you must log in to the secondary BIG-IQ system, click
System
-> BIG-IQ HA
, click the BIG-IQ HA Settings
button, then click the Log Out & Refresh
button. This procedure is required because BIG-IQ handles users and user groups differently than other data synchronized between BIG-IQ systems in an HA pair. If you don't perform this procedure, this new user cannot successfully log in to the secondary system. Create a RADIUS-authenticated user group
Before you can add a RADIUS-authenticated user group, you must set up BIG-IQ to use your company's RADIUS server for user authentication on the
screen.Create a user group to offer individual users the same privileges on F5 BIG-IQ Centralized Management. This user group will be authorized by your RADIUS server.
If a user does not belong to a RADIUS-authenticated user group, authentication will fail.
- At the top of the screen, clickSystem.
- At the left, click.The User Groups screen opens.
- Click theAddbutton.
- In theNamefield, type a name for this new user group.
- From theAuth Providerlist, selectRADIUS.
- In theAttributeandValuefields, type the properties for your RADIUS server.You must use at least one attribute and value, which you can find in in your RADIUS server's dictionary.
- From theAvailable Roleslist, select the user roles that have the privileges you want to grant to this user group and move them to theSelectedlist.
- Click theSave & Closebutton.
If this BIG-IQ is part of an HA pair, you must log in to the secondary BIG-IQ system, click
System
-> BIG-IQ HA
, click the BIG-IQ HA Settings
button, then click the Log Out & Refresh
button. This procedure is required because BIG-IQ handles users and user groups differently than other data synchronized between BIG-IQ systems in an HA pair. If you don't perform this procedure, this new user cannot successfully log in to the secondary system.