radius-server host

Configures the Remote Authentication Dial-In User Service (RADIUS) server.
radius-server host { ipv4-address | host-name | ipv6-address } [ auth-port port-num [ acct-port port-num ] { accounting-only | authentication-only | default } | ssl-auth-port port-num { accounting-only | authentication-only | default | profile profile_name } ] [ key key-string ] [ dot1x | mac-auth | no-login | web-auth ] [ port-only | priority priority-level ] [ status-server off | on ]
no radius-server host { ipv4-address | host-name | ipv6-address } [ auth-port port-num [ acct-port port-num ] { accounting-only | authentication-only | default } | ssl-auth-port port-num { accounting-only | authentication-only | default | profile profile_name } ] [ key key-string ] [ dot1x | mac-auth | no-login | web-auth ] [ port-only | priority priority-level ] [ status-server off | on ]
Command Default

The RADIUS server host is not configured.

Parameters
ipv4-address
Configures the IPv4 address of the RADIUS server.
host-name
Configures the host name of the RADIUS server.
ipv6-address
Configures the IPv6 address of the RADIUS server.
auth-port port-num
Configures the authentication UDP port. The default value is 1812.
acct-port port-num
Configures the accounting UDP port. The default value is 1813.
accounting-only
Configures the server to be used only for accounting.
authentication-only
Configures the server to be used only for authentication.
default
Configures the server to be used for any AAA operation.
profile profile_name
Applies a previously configured authentication profile to an SSL authentication port.
ssl-auth-port port-num
Specifies that the server is a RADIUS server running over a TLS-encrypted TCP session. Only one of auth-port or ssl-auth-port can be specified. If neither is specified, it defaults to the existing default behavior, which uses the default auth-port of 1812 and 1813 for accounting with no TLS encryption. The default destination port number for RADIUS over TLS is TCP/2083.There are no separate ports for authentication, accounting, and dynamic authorization changes. The source port is arbitrary. TLS-encrypted sessions support both IPv4 and IPv6.
accounting-only
Configures the server to be used only for accounting.
authentication-only
Configures the server to be used only for authentication.
default
Configures the server to be used for any AAA operation.
key key-string
Configures the RADIUS key for the server. The key-string can be from 1 through 64 characters in length and must not include a space or any of the following characters: #, {, or }.
dot1x
Configures support for EAP for 802.1X authentication.
mac-auth
Configures the server to be used only for MAC authentication.
no-login
Configures the server not to be used for Telnet, SSH, console, EXEC, or Web-management AAA.
web-auth
Configures the server to be used only for Web authentication.
port-only
Specifies that the server will be used only to authenticate users on ports to which it is mapped.
priority priority-level
Specifies the connection priority of the RADIUS host server. The highest priority is 7. The priority can be configured at a value of 1 through 7. By default (when the priority is not configured), the value is 0.
status-server [ off | on ]
Enables or disables status messages for the RADIUS server host. By default, status-server messages are enabled, and server status is continually checked, resulting in a high number of log messages. As an option, you can use the off setting to disable status-server messages for the configured RADIUS server host.
Modes

Global configuration mode

Usage Guidelines

Use this command to identify a RADIUS server to authenticate access to a RUCKUS device. You can specify up to eight servers. If you add multiple RADIUS authentication servers to the RUCKUS device, the device tries to reach them in the order you add them. To use a RADIUS server to authenticate access to a RUCKUS device, you must identify the server to the RUCKUS device. In a RADIUS configuration, you can designate a server to handle a specific AAA task. For example, you can designate one RADIUS server to handle authorization and another RADIUS server to handle accounting. You can specify individual servers for authentication and accounting, but not for authorization. You can set the RADIUS key for each server.

TLS-encrypted TCP sessions are not supported by management VRF.

The radius-server host command and the radius-server key command must be entered on the same command line to configure the ICX device to authenticate end devices through 802.1x or MAC authentication.

The priority option can be used only with the dot1x, mac-auth, or web-auth authentication options.

The priority option is NOT supported in conjunction with the port-only option.

The recommended best practice is to assign different priorities to different servers. If the same prioriy is assigned to multiple servers, the RADIUS connection request can be sent from any of the servers of the same priority, starting from the last configured server.

The no form of the command removes the RADIUS sever host configuration.

Examples

The following example configures non-default UDP ports for authorization and accounting.

device(config)# radius-server host 1.2.3.4 auth-port 100 acct-port 200
device(config)# show aaa
***** TACACS server not configured
Radius default key: ...
Radius retries: 3
Radius timeout: 3 seconds
Radius Server:     IP=172.26.67.12 SSL Port=2083 Usage=any 
                   Key=...
                   opens=0 closes=0 timeouts=0 errors=0
                   packets in=0 packets out=0
                   IPv4 Radius Source address: IP=0.0.0.0     IPv6 Radius Source Address:     IP=:: 
Radius Server:     IP=1.2.3.4 Auth Port=100 Acct Port=200 Usage=any 
                   Key=...
                   opens=0 closes=0 timeouts=0 errors=0
                   packets in=0 packets out=0
                   IPv4 Radius Source address: IP=0.0.0.0     IPv6 Radius Source Address:     IP=::

The following example shows how to specify different RADIUS servers for authentication and accounting.

device(config)# radius-server host 10.2.3.4 auth-port 1800 acct-port 1850 default key abc
device(config)# radius-server host 10.2.3.5 auth-port 1800 acct-port 1850 authentication-only key def
device(config)# radius-server host 10.2.3.6 auth-port 1800 acct-port 1850 accounting-only key ghi

The following example shows how to map the 802.1X port to a RADIUS server.

device(config)# radius-server host 10.2.3.4 auth-port 1800 acct-port 1850 default key abc dot1x

The following example shows how to configure a RADIUS server for TLS support.

device(config)# radius-server host 172.26.67.12 ssl-auth-port 2083 default key whatever
device(config)# show aaa
***** TACACS server not configured
Radius default key: ...
Radius retries: 3
Radius timeout: 3 seconds
Radius Server:     IP=172.26.67.12 SSL Port=2083 Usage=any 
                   Key=...
                   opens=0 closes=0 timeouts=0 errors=0
                   packets in=0 packets out=0
                   IPv4 Radius Source address: IP=0.0.0.0       IPv6 Radius Source Address:      IP=::

The following example configures the RADIUS server to be used for both MAC authentication and login features.

device# configure terminal
device(config)# radius-server host 10.26.67.13 auth-port 1812 acct-port 1813 default key ruckus mac-auth

The following example uses the RADIUS server for Flexible authentication modules and login features.

device# configure terminal
device(config)# radius-server host 10.26.67.13 auth-port 1812 acct-port 1813 default key ruckus mac-auth dot1x

The following example uses the RADIUS server for Flexible authentication and excludes the use of the server for login features.

device# configure terminal
device(config)# radius-server host 10.26.67.13 auth-port 1812 acct-port 1813 default key ruckus mac-auth dot1x no-login

The following example shows the default profile available in TPM devices (not user configured).

radius-server host 10.177.131.182 ssl-auth-port 2083 profile DEVICE_PROFILE default key 123qwe dot1x mac-auth web-auth

The following example configures a TLS-encrypted session for the RADIUS server. It uses the pre-configured SSL profile "tls-profile." An SSL profile is required for establishing an encrypted TLS session.

device(config)# radius-server host 10.177.131.182 ssl-auth-port 2083 profile tls-profile default key radsec dot1x mac-auth web-auth

The following example configures a RADIUS server host with the highest priority (7) and uses the show radius servers command to confirm the configuration.

device# configure terminal
device(config)# radius-server host 10.177.17.83 auth-port 1812 acct-port 1813 default key 2 $m1y2k3e4y dot1x mac-auth web-auth priority 7

device(config)# show radius servers 
---------------------------------------------------------------------------------------------------
Server                       Type      Opens     Closes   Timeouts   Status     Priority
---------------------------------------------------------------------------------------------------
10.177.17.83                 any         4          3          0     active        7

The following example turns off the status-server messages for the configured RADIUS server host.

device# configure terminal
device(config)# radius-server host 10.177.17.83 auth-port 1812 acct-port 1813 default key 2 $m1y2k3e4y 
dot1x mac-auth web-auth priority 7 status-server off

device(config)# show running-config | in radius
radius-server host 10.177.17.83 auth-port 1812 acct-port 1813 default key 2 $m1y2k3e4y dot1x mac-auth web-auth priority 7 status-server off
History
Release version Command history
08.0.50 This command was updated with the mac-auth and web-auth options.
08.0.80 This command was modified to add the no-login option.
10.0.10 This command was modified to remove the following characters from key key-string syntax: #, {, and }.
10.0.10c This command was modified to add the priority option.
10.0.10c_cd4 This command was modified to add the status-server option.