Community discussions

MikroTik App
 
xander
newbie
Topic Author
Posts: 25
Joined: Mon Feb 27, 2012 7:37 am

Centralized authentication for Winbox admin users

Mon May 06, 2013 9:03 pm

Hi,

I was wondering if it was possible to either use a Mikrotik, or other software application to use as a centralized authentication point? We have many Mikrotik's throughout our company and we wish to move away from having a shared "admin" password because you never know who did what when something wrong happens, so I would like everybody in my team to have their own login, but I don't want to have to manage 20+ logins on all our routers in every branch office etc.

I was wondering, wether with User Manager, or a Radius server on Linux if it was possible to set up credentials for Winbox logins?

Thanks
 
User avatar
boen_robot
Forum Guru
Forum Guru
Posts: 2400
Joined: Thu Aug 31, 2006 4:43 pm
Location: europe://Bulgaria/Plovdiv

Re: Centralized authentication for Winbox admin users

Mon May 06, 2013 9:05 pm

Yes. You could use a RADIUS server like User Manager for example.

To enable the router to authenticate against a RADIUS server, just click the "AAA" button in the users menu, and check the "Use RADIUS" checkbox. The exact RADIUS server parameters can be set at the "Radius" menu.
 
xander
newbie
Topic Author
Posts: 25
Joined: Mon Feb 27, 2012 7:37 am

Re: Centralized authentication for Winbox admin users

Mon May 06, 2013 9:14 pm

I see.

Are all Radius users limited to a single authentication group?

In Winbox, under Users, AAA, there's a "Default Group" drop down, does that mean all users have to use this profile?
The reason why I ask this is because we would like some less experienced users to only be able able to view configuration, issues, logs, etc, but not able to change anything without consulting a senior technician (to avoid issues, like disconnecting a remote site by accident, etc).

Thanks
 
User avatar
boen_robot
Forum Guru
Forum Guru
Posts: 2400
Joined: Thu Aug 31, 2006 4:43 pm
Location: europe://Bulgaria/Plovdiv

Re: Centralized authentication for Winbox admin users

Mon May 06, 2013 9:27 pm

No.

You must configure the RADIUS server to also send an actual group name. AFAIK, if the group doesn't exist, the login will fail, but I don't use RADIUS, so it might be that the default group is used as a fallback then.

(disregarding RADIUS for a second, this is setting is actually used when you call "/user add" from a terminal)
 
xander
newbie
Topic Author
Posts: 25
Joined: Mon Feb 27, 2012 7:37 am

Re: Centralized authentication for Winbox admin users

Mon May 06, 2013 10:22 pm

I see, and I found a tutorial on Freeradius that shows how to pass along a specific group as well.

Thanks for your help! +karma too ;)

Alex
 
tonyd
newbie
Posts: 49
Joined: Fri Jul 20, 2012 3:31 pm

Re: Centralized authentication for Winbox admin users

Thu Aug 01, 2013 2:27 am

Hi, This is a topic I'm interested, could you recall the tut that you indicated you found and post a link?

Thanks

td

Who is online

Users browsing this forum: Bing [Bot], GoogleOther [Bot] and 53 guests