Mapping RADIUS Servers to Ports
As an option, you can configure a RADIUS server to authenticate only ports mapped to it. A RADIUS server that is not explicitly configured as a RADIUS server per port is a global server that can be used to authenticate users on ports to which no RADIUS servers are mapped.
When you map one or more RADIUS servers to a port on a RUCKUS device, the port authenticates users using only the RADIUS servers to which the port is mapped.
When more than one server is mapped to a port, the port tries the servers in the order they are mapped until a server that can perform the requested function is found or until every mapped server in the list has been tried.
If there are no RADIUS servers mapped to a port, the port uses the global servers for authentication.
Keep the following points in mind when mapping ports to RADIUS servers.
- This feature works with 802.1X and MAC authentication only.
- The priority option is not supported in conjunction with the port-only option.
- You can define a maximum of eight RADIUS servers per RUCKUS device.
- You can map a RADIUS server to a physical port only. You cannot map a RADIUS server to a VE.
Complete the following steps to map a RADIUS server or a set of RADIUS servers to specific ports.
- Enter global configuration mode.
- (Optional) Configure one or more
RADIUS servers to authenticate only ports that are explicitly mapped to it. Use
the port-only keyword as part of each
radius-server hostcommand.device(config)# radius-server host 10.10.10.103 auth-port 1812 acct-port 1813 default key mykeyword dot1x port-only device(config)# radius-server host 10.10.10.104 auth-port 1812 acct-port 1813 default key mykeyword dot1x port-only
RADIUS servers 10.10.10.103 and 10.10.10.104 are configured with the port-only option so that they authenticate users only on ports to which the servers are mapped. - Configure 802.1x or MAC Auth as
the authentication method to be used on a specific port.Note: Refer to Configuring Flexible Authentication for more information on configuring authentication on a port.
- Enter interface configuration sub-mode for the port.
- Enter the
use-radius-servercommand followed by the IP address of the authentication server for each RADIUS server to be mapped to the port.device(config-if-e1000-3/1/1)
# use-radius-server 10.10.10.103device(config-if-e1000-3/1/1)# use-radius-server 10.10.10.110The example maps two RADIUS authentication servers to port 3/1/1.
The following examples map RADIUS servers to specific ports.
device# configure terminal device(config)# authentication device(config-authen)# dot1x enable device(config-authen)# dot1x enable ethernet 3/1/1 device(config-authen)# dot1x port-control auto ethernet 3/1/1 device(config-authen)# exit device(config)# interface ethernet 3/1/1 device(config-if-e1000-3/1/1)# use-radius-server 10.10.10.103 device(config-if-e1000-3/1/1)# use-radius-server 10.10.10.110 device(config-if-e1000-3/1/1)# end
The example uses the dot1x port-control
command to authorize port 3/1/1, which is 802.1X enabled, once the ICX client has
been authenticated by the authentication server. The example configures two RADIUS
servers for port 3/1/1 to use. The port first sends a RADIUS request to the RADIUS
server with IP address 10.10.10.103 because it is the first server mapped to the
port. If the request fails, the port sends a request to the RADIUS server at IP
address 10.10.10.110.
The following example enables MAC authentication on port 2/1/1 and configures authentication through the same RADIUS servers as in the previous example.
device# configure terminal device(config)# authentication device(config-authen)# mac-auth enable device(config-authen)# mac-auth enable ethernet 2/1/1 device(config-authen)# exit device(config)# interface ethernet 2/1/1 device(config-if-e1000-2/1/1)# use-radius-server 10.10.10.103 device(config-if-e1000-2/1/1)# use-radius-server 10.10.10.110 device(config-if-e1000-2/1/1)# end