radius-server host
radius-server host
{
ipv4-address
|
host-name
|
ipv6-address
}
[
auth-port
port-num
[
acct-port
port-num
]
{
accounting-only
|
authentication-only
|
default
}
|
ssl-auth-port
port-num
{
accounting-only
|
authentication-only
|
default
|
profile
profile_name
}
]
[
key
key-string
]
[
dot1x
|
mac-auth
|
no-login
|
web-auth
]
[
port-only
|
priority
priority-level
]
[
status-server
off
|
on
]no radius-server host
{
ipv4-address
|
host-name
|
ipv6-address
}
[
auth-port
port-num
[
acct-port
port-num
]
{
accounting-only
|
authentication-only
|
default
}
|
ssl-auth-port
port-num
{
accounting-only
|
authentication-only
|
default
|
profile
profile_name
}
]
[
key
key-string
]
[
dot1x
|
mac-auth
|
no-login
|
web-auth
]
[
port-only
|
priority
priority-level
]
[
status-server
off
|
on
]The RADIUS server host is not configured.
- profile profile_name
- Applies a previously configured authentication profile to an SSL authentication port.
- ssl-auth-port port-num
- Specifies that the server is a RADIUS server running over a TLS-encrypted TCP session. Only one of auth-port or ssl-auth-port can be specified. If neither is specified, it defaults to the existing default behavior, which uses the default auth-port of 1812 and 1813 for accounting with no TLS encryption. The default destination port number for RADIUS over TLS is TCP/2083.There are no separate ports for authentication, accounting, and dynamic authorization changes. The source port is arbitrary. TLS-encrypted sessions support both IPv4 and IPv6.
- key key-string
- Configures the RADIUS key for the server. The key-string can be from 1 through 64 characters in length and must not include a space or any of the following characters: #, {, or }.
- port-only
- Specifies that the server will be used only to authenticate users on ports to which it is mapped.
- priority priority-level
- Specifies the connection priority of the RADIUS host server. The highest priority is 7. The priority can be configured at a value of 1 through 7. By default (when the priority is not configured), the value is 0.
- status-server [ off | on ]
- Enables or disables status messages for the RADIUS server host. By default, status-server messages are enabled, and server status is continually checked, resulting in a high number of log messages. As an option, you can use the off setting to disable status-server messages for the configured RADIUS server host.
Global configuration mode
Use this command to identify a RADIUS server to authenticate access to a RUCKUS device. You can specify up to eight servers. If you add multiple RADIUS authentication servers to the RUCKUS device, the device tries to reach them in the order you add them. To use a RADIUS server to authenticate access to a RUCKUS device, you must identify the server to the RUCKUS device. In a RADIUS configuration, you can designate a server to handle a specific AAA task. For example, you can designate one RADIUS server to handle authorization and another RADIUS server to handle accounting. You can specify individual servers for authentication and accounting, but not for authorization. You can set the RADIUS key for each server.
TLS-encrypted TCP sessions are not supported by management VRF.
The
radius-server host command and the
radius-server key command must be entered on the same command line to configure the ICX device to authenticate
end devices through 802.1x or MAC authentication.
The priority option can be used only with the dot1x, mac-auth, or web-auth authentication options.
The priority option is NOT supported in conjunction with the port-only option.
The recommended best practice is to assign different priorities to different servers. If the same prioriy is assigned to multiple servers, the RADIUS connection request can be sent from any of the servers of the same priority, starting from the last configured server.
The
no form of the command removes the RADIUS sever host configuration.
The following example configures non-default UDP ports for authorization and accounting.
device(config)# radius-server host 1.2.3.4 auth-port 100 acct-port 200
device(config)# show aaa
***** TACACS server not configured
Radius default key: ...
Radius retries: 3
Radius timeout: 3 seconds
Radius Server: IP=172.26.67.12 SSL Port=2083 Usage=any
Key=...
opens=0 closes=0 timeouts=0 errors=0
packets in=0 packets out=0
IPv4 Radius Source address: IP=0.0.0.0 IPv6 Radius Source Address: IP=::
Radius Server: IP=1.2.3.4 Auth Port=100 Acct Port=200 Usage=any
Key=...
opens=0 closes=0 timeouts=0 errors=0
packets in=0 packets out=0
IPv4 Radius Source address: IP=0.0.0.0 IPv6 Radius Source Address: IP=::
The following example shows how to specify different RADIUS servers for authentication and accounting.
device(config)# radius-server host 10.2.3.4 auth-port 1800 acct-port 1850 default key abc device(config)# radius-server host 10.2.3.5 auth-port 1800 acct-port 1850 authentication-only key def device(config)# radius-server host 10.2.3.6 auth-port 1800 acct-port 1850 accounting-only key ghi
The following example shows how to map the 802.1X port to a RADIUS server.
device(config)# radius-server host 10.2.3.4 auth-port 1800 acct-port 1850 default key abc dot1x
The following example shows how to configure a RADIUS server for TLS support.
device(config)# radius-server host 172.26.67.12 ssl-auth-port 2083 default key whatever
device(config)# show aaa
***** TACACS server not configured
Radius default key: ...
Radius retries: 3
Radius timeout: 3 seconds
Radius Server: IP=172.26.67.12 SSL Port=2083 Usage=any
Key=...
opens=0 closes=0 timeouts=0 errors=0
packets in=0 packets out=0
IPv4 Radius Source address: IP=0.0.0.0 IPv6 Radius Source Address: IP=::
The following example configures the RADIUS server to be used for both MAC authentication and login features.
device# configure terminal device(config)# radius-server host 10.26.67.13 auth-port 1812 acct-port 1813 default key ruckus mac-auth
The following example uses the RADIUS server for Flexible authentication modules and login features.
device# configure terminal device(config)# radius-server host 10.26.67.13 auth-port 1812 acct-port 1813 default key ruckus mac-auth dot1x
The following example uses the RADIUS server for Flexible authentication and excludes the use of the server for login features.
device# configure terminal device(config)# radius-server host 10.26.67.13 auth-port 1812 acct-port 1813 default key ruckus mac-auth dot1x no-login
The following example shows the default profile available in TPM devices (not user configured).
radius-server host 10.177.131.182 ssl-auth-port 2083 profile DEVICE_PROFILE default key 123qwe dot1x mac-auth web-auth
The following example configures a TLS-encrypted session for the RADIUS server. It uses the pre-configured SSL profile "tls-profile." An SSL profile is required for establishing an encrypted TLS session.
device(config)# radius-server host 10.177.131.182 ssl-auth-port 2083 profile tls-profile default key radsec dot1x mac-auth web-auth
The following example configures a RADIUS
server host with the highest priority (7) and uses the show radius servers
command to confirm the configuration.
device# configure terminal device(config)# radius-server host 10.177.17.83 auth-port 1812 acct-port 1813 default key 2 $m1y2k3e4y dot1x mac-auth web-auth priority 7 device(config)# show radius servers --------------------------------------------------------------------------------------------------- Server Type Opens Closes Timeouts Status Priority --------------------------------------------------------------------------------------------------- 10.177.17.83 any 4 3 0 active 7
The following example turns off the status-server messages for the configured RADIUS server host.
device# configure terminal device(config)# radius-server host 10.177.17.83 auth-port 1812 acct-port 1813 default key 2 $m1y2k3e4y dot1x mac-auth web-auth priority 7 status-server off device(config)# show running-config | in radius radius-server host 10.177.17.83 auth-port 1812 acct-port 1813 default key 2 $m1y2k3e4y dot1x mac-auth web-auth priority 7 status-server off