Go to the table of contents Go to the previous page Go to the next page View or print as PDF
The RADIUS user identification process
Using RADIUS Agent | Web Protection Solutions |v8.4.x, v8.5.x | 29-Apr-2022
Without RADIUS Agent, remote users are authenticated by a RADIUS client (RAS server, VPN server, or firewall) as follows:
1.
2.
3.
4.
With RADIUS Agent in place in your network, the user authentication process allows the agent to process and transmit remote authentication requests and provide user information to Filtering Service for use in policy enforcement and reporting.
Note that Forcepoint recommends installing RADIUS Agent on a machine separate from the RADIUS server machine. This prevents port and IP address conflicts between RADIUS Agent and the RADIUS server.
The transparent identification process is as follows:
1.
 
Note 
2.
3.
 
Note 
4.
5.
 
Note 
6.
RADIUS Agent evaluates the response from the RADIUS server. If the RADIUS message received is an authentication rejection, RADIUS Agent removes the corresponding entry from its user map.
If the RADIUS packet received is an authentication acceptance, RADIUS Agent copies the corresponding entry to its main user map (a listing of full domain/user name/IP address entries).
7.
8.
 
Note 
9.
10.

Go to the table of contents Go to the previous page Go to the next page View or print as PDF
Copyright 2022 Forcepoint. All rights reserved.