Showing posts with label tacacs. Show all posts
Showing posts with label tacacs. Show all posts

Tuesday, September 18, 2018

Radiator as a Cisco ACS replacement

Since Cisco announced the end of sale of their Secure Access Control System (Cisco ACS), customers have contacted Radiator Software looking for a replacement solution, and they have found Radiator AAA Server Software to be just the alternative they need. Radiator is a cost-effective, flexible solution that is known in the market as the “Swiss Army of AAA Servers”.

Radiator AAA Server Software is actively developed and it runs with a variety of platforms, including Linux, Windows, and others. You can be sure that you will have a supported, continuously developed AAA solution that is always kept up to date for years to come. Radiator has at least two releases per year, with interim patches made for security and other urgent needs.

Making it a flexible solution with multi-vendor support, key features of Radiator include:

  • Supports authentication by over 60 different types of methods
  • Interoperates with a huge range of devices, databases, billing packages, and tokens
  • Includes RadSec - secure, reliable RADIUS proxying
  • Includes Diameter - the RADIUS successor protocol used already by mobile operators
  • Includes TACACS+ - for infrastructure management
  • Integration with AD, LDAP, SQL databases among others
  • Accounting logs in variety of formats to be integrated with external systems
  • See also full feature list 

How migration to Radiator works?

When doing the migration to Radiator, you do not need to have new appliances; Radiator can be cost-efficiently fitted into your current infrastructure.

All you need is to install Radiator into your preferred platform, implement the initial configuration, and integrate Radiator to your preferred database. The use of a separate database enables your organization a secure way to store user credentials and data. Additionally, it is possible to include management and logging systems, which you may already have in use. When doing the migration, our team can provide you with assistance and experience from a wide range of use cases.

Typical Radiator set-up in a Wi-Fi authentication use case using RADIUS and TACACS+.

You do not need to worry about complicated licensing; all you need is a Radiator AAA Server Software license pack, available from one server license, two server license for high-availability, and unlimited server count license for large scale deployments. If you need an additional AAA server for a different use case within your organization, you can use a remaining available license, or upgrade your existing pack.

Would you like to know more?

With Radiator, you get direct professional technical support for configuration, deployment, and custom development. Our support packages range from basic email support to 24x7 telephone support.

Our consulting services are available to assist with migration projects. As we have had a wide range of customers with different needs migrating to Radiator, we can easily tailor a cost-effective consulting package for your needs. Thanks to our experience with similar projects, Radiator configuration can be adjusted to new environments without any extra hassle. Our customers include ISPs, enterprises, carriers, universities, public organizations, and utility companies.

If you would like to know more about Radiator, licensing options, and support, please contact our team at sales@radiatorsoftware.com

Blog post revised Feb 2nd 2022.

Friday, August 31, 2018

Radiator interacting with Microsoft Azure Multi-Factor Authentication

One of Radiator’s key strengths is flexibility in different environments and authentication use cases.

Recently, a customer had a new case for authenticating network device administrators with Microsoft Azure Multi-Factor Authentication (MFA). The devices use TACACS+ and a solution was required to integrate with Azure MFA Radius. Thanks to the flexibility of Radiator, this can be done without any extra hassle.

When a user logs in, the device sends the username, static password and one-time passcode with TACACS+ authentication request to Radiator. Radiator processes the TACACS+ request and starts MFA authentication by first sending the password as RADIUS Access-Request. Azure MFA responds by replying with Access-Challenge prompting for the passcode. In turn, Radiator responds with password reminder (passcode of 6 numbers) to complete the authentication.

After this, authentication REPLY is delivered to the TACACS+ client and access is granted.



Would you like to know more?

In many recent customer cases, we have implemented various authentication solutions to interact with Microsoft Azure, including the Multi-Factor Authentication use case mentioned above. We are happy to tell more about this and other use cases. If you would like to know more, please contact info@radiatorsoftware.com

Monday, January 15, 2018

Radiator use case: Secure authentication to network devices in corporate network

Radiator AAA Server Software has countless use cases in enterprises. This blog text introduces you a specific use case of real life: authentication of network administrators who configure and maintain corporate network infrastructure. This requires extra security that Radiator is able to provide.



In the example use case, the admins log in to Broadband Network Gateways (BNG) with TACACS+ protocol using their own authentication credentials and passwords. For essential network equipment, a secure two-factor authentication (2FA) is used. Radiator supports a wide range of interfaces for these kinds of authentication use cases. Our customers are free to choose the interfaces and protocols that suit to their own needs.

LDAP user database provides the first factor authentication in the example use case. The second factor is handled by Duo Security.

With AuthBy DUO module, you can configure Radiator to integrate with Duo Security API, which in this case provides the second phase of authentication with Duo Security’s phone application. After the authentication has been confirmed by the application, Radiator will grant access to the network.

Using different 2FA solutions

In addition to TACACS+ protocol, Radiator supports wide range of different authentication protocols that you can use – including RADIUS. It is also possible to use different methods for the first factor authentication and second factor authentication. Radiator supports a number of interfaces suitable for the second factor authentication, and we already have use cases with several different solutions. These interfaces are included in Radiator licences.

If you have any needs for two-factor authentication in your own network, please contact our team at info@radiatorsoftware.com. We are happy to share our experience and help you with your own project.

Updated 6th of February 2018:

You can also learn more about the technical architecture from our earlier post: Secure your network and services with Radiator two-factor authentication.

Tuesday, August 2, 2016

Secure your network and services with Radiator two-factor authentication

Modern services all around the Internet offer different two-factor authentication solutions. They provide stronger security than using only username and password. Two-factor authentication requires a combination of something the user knows and something the user possesses. One common combination is the username and PIN or password with a physical token, such as a specific device, smart card, or mobile phone. The two-factor secured service may range from a web service to a network device to a remote VPN (Virtual Private Network) access – wherever stronger security is needed.

Figure 1: Radiator based two-factor authentication and authorisation architecture

Radiator AAA Server Software provides flexible, interoperable, and scalable two-factor AAA (Authentication, Accounting, and Authorisation) service for any device or service, which can use RADIUS, TACACS, or TACACS+ interface for AAA. The VPN devices can authenticate remote employees, the network devices can authorise administrators, and the web services can identify the users with secure two-factor authentication. All you need is Radiator-based two-factor AAA service and a free mobile phone app, such as Google Authenticator, Microsoft Authenticator, or some other OTP/TOTP/HOTP app. The authenticator app is paired with Radiator two-factor AAA service and particular user credentials, and two-factor authentication are ready to be used.

Another major benefit of using Radiator is its legendary interoperability. Radiator can combine complementary AAA information and functions from Active Directory, LDAP, and even 3rd party two-factor services, such as RSA SecurID, YubiKey, Duo Security, and Vasco Digipass. It can check existence and validity of a user from Active Directory, retrieve a proper VPN group, perform two-factor authentication using TOTP (Time-based One-time Password Algorithm), and then combine the results to a RADIUS authentication and authorisation response, which is sent back to a Cisco ASA VPN device.

Radiator can also extend the functionalities of 3rd party two-factor authentication services by translating and complementing AAA interactions between services and devices. For example, Radiator combines fine-grained TACACS(+)- or RADIUS-based network device configuration authorisation with existing user directories and two-factor authentication. The two-factor authentication data may be retrieved from Radiator itself or some 3rd party service. With the help of Radiator’s extendable two-factor modules, Radiator also supports SMS transfer of one-time-passwords, when using tokens or authenticator app is not feasible.

Radiator and its two-factor authentication functionalities have already been deployed in several different environments such as:
  • Fortune 250 company uses Radiator for two-factor authentication of their global VPN network.
  • IT departments of world’s two top universities provide VPN service for their employees, partners, and students utilising Radiator’s capability to combine Duo Security two-factor authentication service to additional LDAP directory checks.
  • Nordic operator provides multi-function (RSA SecurID, SMS) two-factor authentication service to their enterprise customers.

Would you like to know more?

Contact our team at info@open.com.au to set up a meeting, where we can discuss how Radiator could help you in securing access to your services or network with two-factor authentication.

Wednesday, August 13, 2014

Welcome to the Radiator AAA Server Cookbook




Radiator RADIUS server has been around since the early days of Internet service providers. It has and is still been developed together with our customers and partners around the world. In fact, during its lifetime, so much additional functionality and protocols have been added to Radiator, that instead of just RADIUS server, we should talk more about Radiator AAA (Authentication, Authorisation and Accounting) server. Our new extension packs, Radiator SIM Pack and Radiator Diameter Pack, extend Radiator far beyond of just RADIUS and TACACS protocol functionality. Radiator runs and scales from small embedded devices like Raspberry Pi to carrier grade network equipment and server platforms including Linux, UNIX(-like) and Windows server platforms. Radiator can be run on actual hardware or virtualised in the cloud, the major design point being that Radiator is flexible, scalable and interoperable for customers and integrators to be used everywhere in the AAA infrastructure.

The challenge in marketing Radiator is that because it can do almost everything, where should and could we start in describing what the Radiator can be used for. In trade fairs it is always possible to ask the visitors what does their organisation do and then select a suitable pitch or angle for that particular segment. Doing the same on a web page or paper brochures would require us to spend more resources to write and polish content instead of actually doing the development and real things with Radiator.

For years Radiator has been delivered with comprehensive collection of configuration examples called goodies. Our customers appreciate this and that is why we get contributions from them both in code, configurations etc. However for new customers or ones looking for solution for their problems, this functionality and applicability of Radiator is hidden knowledge. In this Radiator Cookbook, we aim to bring forward old and proven recipes as well as new and experimental ones to use Radiator for solving various customer challenges. This will not be a high frequency blog, but more like one where  you can search for recipes, solutions and inspiration how to use Radiator and where to find more information about it.

Welcome.

The Radiator Diameter Pack is now known as Radiator Service Provider Pack.