I'm looking at doing a lot of RADIUS authentication on my network in the very near future, but I'm not sure I understand the whole realms concept.
My assumption thus far is that I can create a functional realm for different functions. My situation dictates that I should setup three realms:
1) Netadmin realm - this will authenticate the network admins for switch and router management through the CLI
2) VPN realm - this will authenticate all VPN users on my network against an Active Directory database
3) 802.1x realm - this will authenticate all physical ports on the network against an Active Directory database for users plugging into my network
So am I correct? Is a realm under RADIUS similar to an OU in AD where it has it's own users, permissions, properties, etc?
My assumption thus far is that I can create a functional realm for different functions. My situation dictates that I should setup three realms:
1) Netadmin realm - this will authenticate the network admins for switch and router management through the CLI
2) VPN realm - this will authenticate all VPN users on my network against an Active Directory database
3) 802.1x realm - this will authenticate all physical ports on the network against an Active Directory database for users plugging into my network
So am I correct? Is a realm under RADIUS similar to an OU in AD where it has it's own users, permissions, properties, etc?
