Enable external authentication for users on the CDO

Enable external authentication for users to allow the Cloud-Delivered Firewall Management Center to verify user credentials with an LDAP or RADIUS server, enhancing security and centralized user management.

When you enable external authentication for management users, the Cloud-Delivered Firewall Management Center verifies the user credentials with an LDAP or RADIUS server as specified in an External Authentication object.

Before you begin

Add one or more external authentication objects according to Add an LDAP external authentication object for the Security Cloud Control and Add a RADIUS external authentication object for Security Cloud Control.

Follow these steps to enable external authentication for users on the CDO:

Procedure


Step 1

Choose Administration > Users.

Step 2

Click External Authentication.

Step 3

Set the default user role for external web interface users.

If a user does not have a role, they cannot perform any actions. Roles set in the external authentication object override the default user role.

  1. Click the Default User Role value (by default, no selection).

  2. In the Default User Role Configuration dialog box, check the role or roles that you want to use.

  3. Click Save.

Step 4

Click the Slider enabled (slider enabled) next to the each external authentication object that you want to use. If you enable more than one object, users are compared against servers in the specified order. Refer to the next step to reorder servers.

If you enable shell authentication, you must enable an external authentication object that includes a CLI Access Filter. Also, CLI access users can only authenticate against the server whose authentication object is highest in the list.

Step 5

(Optional) Drag and drop servers to change the order in which the system accesses them during authentication.

Step 6

From the Shell Authentication drop-down list, click Enabled if you want to allow CLI access for external users.

Note

The multidomain feature is not supported in CLI. Therefore, the Shell Authentication option is available only in the Global domain and not in Subdomains.

The first external authentication object name is shown next to the Enabled option to remind you that only the first object is used for CLI.

Step 7

Click Save and Apply.


When you complete this task, the system enables external authentication for users. Cloud-Delivered Firewall Management Center verifies their credentials with the LDAP or RADIUS servers you configured and assigns roles as you specified.