Access rights transfer

The authorization of the user is stored in the RADIUS server. When a request arrives, the RADIUS server sends the access- and function rights to the LANCOM along with the login data, which then logs in the user with the appropriate privileges.

Access rights are usually defined in the RADIUS management privilege level (attribute 136), and the LANCOM simply maps this value to its internal access rights (option: "Mapped"). The attribute can have the following values, which are then mapped by the LANCOM:
However, some RADIUS servers may also need to assign function rights, they may use attribute 136 differently, or they may use different, vendor-specific attributes for the authorization. In this case, you must select the vendor-specific attributes. These attributes are defined as follows, based on the LANCOM vendor ID '2356':
The transferred access-right values are identical to the above. If the RADIUS server also has to transfer function rights, you achieve this as follows:
  1. Open the console for the LANCOM.
  2. Change to the directory Setup > Config > Admins.
  3. The command set? shows you the current mapping of the function rights to the corresponding hexadecimal code (e.g. Device-Search (0x80)).
  4. To combine function rights, you add their hex values together.
  5. Convert the hexadecimal value to a decimal number.
  6. By using this decimal value in the function rights ID, you can transfer the corresponding rights.
Telnet path:
Setup > Config > Radius
Possible values:
Vendor-specific
Mapped
Default:
Vendor-specific