RADIUS Authentication and Accounting
Configuring the Switch for RADIUS Authentication
4-6
Configuring the Switch for RADIUS
Authentication
RADIUS Authentication Commands
aaa authentication
< console | telnet | ssh > < enable | login > radius
< local | none >
[no] radius-server host < IP-address >
[auth-port < port-number >]
[acct-port < port-number >]
[key < server-specific key-string >]
[no] radius-server key < global key-string >
radius-server timeout < 1 - 15>
radius-server retransmit < 1 - 5 >
[no] radius-server dead-time < 1 - 1440 >
show radius
[< host < ip-address>]
show authentication
show radius authentication
Outline of the Steps for Configuring RADIUS
Authentication
There are three main steps to configuring RADIUS authentication:
1.
Configure RADIUS authentication for controlling access through one or
more of the following
•
Serial port
•
Telnet
•
SSH
•
Port-Access (802.1x)
2.
Configure the switch for accessing one or more RADIUS servers (one
primary server and up to two backup servers):
Page
4-8
4-8
4-8
4-10
4-10
4-10, 4-20
4-10
4-12
4-12
4-12
4-14
4-25
4-25
4-27
4-27