Configuring Authentication-method Lists for RADIUS

You can use RADIUS to authenticate Telnet or SSH access and access to the Privileged EXEC and global configuration levels of the CLI. When you configure authentication-method lists for RADIUS, you must create an authentication-method list for Telnet or SSH CLI access and a second separate authentication-method list for access to the Privileged EXEC and global configuration levels of the CLI.

Within the authentication-method list, RADIUS is specified as the primary authentication method, and other authentication methods are specified as alternates. If RADIUS authentication fails, the device tries the alternate authentication methods in the order they appear in the list.

Note: For examples of how to define authentication-method lists for types of authentication other than RADIUS, refer to Authentication-Method List Overview.

Perform the following steps to configure authentication-method lists for remote and CLI access.

Note: Telnet and SSH are enabled by default in FastIron release 09.0.00 and later releases.
Note: The aaa authorization exec default radius command must be configured before RADIUS can be configured for login authentication.

  1. Enter global configuration mode.
    device# configure terminal
  2. If it is not already configured, configure the AAA authorization default as RADIUS, followed by any alternative methods you want to configure.
    device(config)# aaa authorization exec default radius local
  3. Enter the aaa authentication login command followed by the desired authentication-method list parameters.
    Note: Refer to Authentication-Method Values for available RADIUS authentication-method list parameters.
    The following example creates an authentication-method list for securing remote Telnet or SSH access to the CLI.
    device(config)# aaa authentication login default radius local
    
    In the example, the default parameter specifies that the methods listed on the same line form the default authentication-method list. The example configures RADIUS as the primary authentication method for securing remote Telnet or SSH access to the CLI. If RADIUS authentication fails due to a server error, local authentication is used instead. If local authentication fails, access is not granted.
  4. Configure authentication methods for access to the Privileged EXEC and global configuration levels of the CLI. Enter the aaa authentication enable command followed by desired parameters.
    The following example configures authentication methods for securing access to the Privileged EXEC level and CONFIG levels of the CLI.
    device(config)# aaa authentication enable default radius local
    The example configures RADIUS as the primary authentication method for securing access to the Privileged EXEC and CONFIG levels of the CLI. If RADIUS authentication fails due to a server error, local authentication is used instead. If local authentication fails, access to the Privileged EXEC and CONFIG levels of the CLI is not allowed.