Enable external authentication for users on the CDO
Enable external authentication for users to allow the Cloud-Delivered Firewall Management Center to verify user credentials with an LDAP or RADIUS server, enhancing security and centralized user management.
When you enable external authentication for management users, the Cloud-Delivered Firewall Management Center verifies the user credentials with an LDAP or RADIUS server as specified in an External Authentication object.
Before you begin
Add one or more external authentication objects according to Add an LDAP external authentication object for the Security Cloud Control and Add a RADIUS external authentication object for Security Cloud Control.
Follow these steps to enable external authentication for users on the CDO:
Procedure
Step 1 | Choose . | ||
Step 2 | Click External Authentication. | ||
Step 3 | Set the default user role for external web interface users. If a user does not have a role, they cannot perform any actions. Roles set in the external authentication object override the default user role.
| ||
Step 4 | Click the Slider enabled ( If you enable shell authentication, you must enable an external authentication object that includes a CLI Access Filter. Also, CLI access users can only authenticate against the server whose authentication object is highest in the list. | ||
Step 5 | (Optional) Drag and drop servers to change the order in which the system accesses them during authentication. | ||
Step 6 | From the Shell Authentication drop-down list, click Enabled if you want to allow CLI access for external users.
The first external authentication object name is shown next to the Enabled option to remind you that only the first object is used for CLI. | ||
Step 7 | Click Save and Apply. |
When you complete this task, the system enables external authentication for users. Cloud-Delivered Firewall Management Center verifies their credentials with the LDAP or RADIUS servers you configured and assigns roles as you specified.
