立即与支持人员聊天
与支持团队交流

Defender 6.4 - Administration Guide

Getting started Managing Defender objects in Active Directory Configuring security tokens Securing VPN access Securing Web sites Securing Windows-based computers Defender Management Portal (Web interface) Securing PAM-enabled services Delegating Defender roles, tasks, and functions Automating administrative tasks Administrative templates Integration with Active Roles Push Notifications Appendices
Appendix A: Enabling diagnostic logging Appendix B: Troubleshooting common authentication issues Appendix C: Troubleshooting DIGIPASS token issues Appendix D: Defender classes and attributes in Active Directory Appendix E: Defender Event Log messages Appendix F: Defender Client SDK Appendix G: Defender Web Service API

Policy tab

This tab allows you to view the current or assign a new Defender Security Policy to the Access Node. The tab has the following elements:

  • Assigned Policy  Shows the Defender Security Policy that is currently assigned to the Access Node. When there is no Defender Security Policy assigned to the Access Node, this option displays <undefined>.
  • Select  Allows you to select a Defender Security Policy to assign to the Access Node.
  • Clear  Unassigns the current Defender Security Policy from the Access Node.
  • Effective  Click this button to view the Defender Security Policy settings that will apply to a specific user for a particular Defender Security Server/Access Node combination. The window that opens looks similar to the following:

 

 

  • Click the Select button to select the user for whom you want to view the Defender Security Policy that will apply.
  • The DSS list shows the Defender Security Server that is currently selected for the user. If necessary, select any other Defender Security Server.
  • The DAN list shows the Access Node that is currently selected for the user. If necessary, select any other Access Node.
  • The Effective Policy area displays the Defender Security Policy details and authentication settings that will be effective when the user authenticates via Defender.

RADIUS Payload tab

This tab allows you to view the current and assign a new RADIUS payload to the Access Node. The tab has the following elements:

  • Assigned Payload  Shows the RADIUS payload that is currently assigned to the Access Node. When there is no RADIUS payload assigned to the Access Node, this option displays <undefined>.
  • Select  Allows you to select a RADIUS payload to assign to the Access Node.
  • Clear  Unassigns the current RADIUS payload from the Access Node.
  • Inherit payload entries from parent. Include these with entries explicitly defined here.  When selected, causes the Access Node to inherit RADIUS payload from the Defender Security Servers to which the Access Node is assigned.
  • Effective  Click this button to view the RADIUS payload that will apply to a specific user for a particular Defender Security Server/Access Node combination. The windows that opens looks similar to the following:

     

 

Click the Select button to select the user for whom you want to view the RADIUS payload that will apply.

The DSS list shows the Defender Security Server that is currently selected for the user. If necessary, select any other Defender Security Server.

The DAN list shows the Access Node that is currently selected for the user. If necessary, select any other Access Node.

The Effective Payload area displays the details of the RADIUS payload that will be effective when the selected user authenticates via Defender.

Managing Defender Security Servers

Defender Security Server is the point in your network where user authentication is performed. If authentication is successful, the user is allowed access to the network.

Creating a Defender Security Server object

To create a Defender Security Server object

  1. On the computer where the Defender Administration Console is installed, open the Active Directory Users and Computers tool (dsa.msc).
  2. In the left pane (console tree), expand the appropriate domain node, and then expand the Defender container.
  3. Right-click the Security Servers container, point to New, and then click Defender Security Server.

    A wizard starts.

  4. In the Enter a name, IP address and description for the Security Server step, use the following options:
    • Name  Type a name for the Defender Security Server object to be created in Active Directory. This name can be different from the name of the computer on which the Defender Security Server component is installed.
    • IP Address  Type the IP address of the computer on which you have installed the Defender Security Server component.
    • Description  Type a friendly Defender Security Server description to be displayed in Active Directory.
  5. Complete the wizard to create the Defender Security Server object in Active Directory.

After creating a Defender Security Server object, you need to modify its properties to assign a Defender Security Policy, Access Node, and RADIUS payload to that object. For more information, see Modify Defender Security Server object properties.

相关文档

The document was helpful.

选择评级

I easily found the information I needed.

选择评级