Mapping RADIUS Servers to Ports

As an option, you can configure a RADIUS server to authenticate only ports mapped to it. A RADIUS server that is not explicitly configured as a RADIUS server per port is a global server that can be used to authenticate users on ports to which no RADIUS servers are mapped.

When you map one or more RADIUS servers to a port on a RUCKUS device, the port authenticates users using only the RADIUS servers to which the port is mapped.

When more than one server is mapped to a port, the port tries the servers in the order they are mapped until a server that can perform the requested function is found or until every mapped server in the list has been tried.

If there are no RADIUS servers mapped to a port, the port uses the global servers for authentication.

Keep the following points in mind when mapping ports to RADIUS servers.

  • This feature works with 802.1X and MAC authentication only.
  • The priority option is not supported in conjunction with the port-only option.
  • You can define a maximum of eight RADIUS servers per RUCKUS device.
  • You can map a RADIUS server to a physical port only. You cannot map a RADIUS server to a VE.

Complete the following steps to map a RADIUS server or a set of RADIUS servers to specific ports.

  1. Enter global configuration mode.
    device# configure terminal
    device(config)#
    
  2. (Optional) Configure one or more RADIUS servers to authenticate only ports that are explicitly mapped to it. Use the port-only keyword as part of each radius-server host command.
    device(config)# radius-server host 10.10.10.103 auth-port 1812 acct-port 1813 default key mykeyword dot1x port-only
    device(config)# radius-server host 10.10.10.104 auth-port 1812 acct-port 1813 default key mykeyword dot1x port-only
    
    RADIUS servers 10.10.10.103 and 10.10.10.104 are configured with the port-only option so that they authenticate users only on ports to which the servers are mapped.
  3. Configure 802.1x or MAC Auth as the authentication method to be used on a specific port.
    Note: Refer to Configuring Flexible Authentication for more information on configuring authentication on a port.
  4. Enter interface configuration sub-mode for the port.
    device(config)# interface ethernet 3/1/1
  5. Enter the use-radius-server command followed by the IP address of the authentication server for each RADIUS server to be mapped to the port.
    device(config-if-e1000-3/1/1)# use-radius-server 10.10.10.103
    device(config-if-e1000-3/1/1)# use-radius-server 10.10.10.110
    The example maps two RADIUS authentication servers to port 3/1/1.

The following examples map RADIUS servers to specific ports.

device# configure terminal
device(config)# authentication
device(config-authen)# dot1x enable
device(config-authen)# dot1x enable ethernet 3/1/1
device(config-authen)# dot1x port-control auto ethernet 3/1/1
device(config-authen)# exit
device(config)# interface ethernet 3/1/1
device(config-if-e1000-3/1/1)# use-radius-server 10.10.10.103
device(config-if-e1000-3/1/1)# use-radius-server 10.10.10.110
device(config-if-e1000-3/1/1)# end

The example uses the dot1x port-control command to authorize port 3/1/1, which is 802.1X enabled, once the ICX client has been authenticated by the authentication server. The example configures two RADIUS servers for port 3/1/1 to use. The port first sends a RADIUS request to the RADIUS server with IP address 10.10.10.103 because it is the first server mapped to the port. If the request fails, the port sends a request to the RADIUS server at IP address 10.10.10.110.

The following example enables MAC authentication on port 2/1/1 and configures authentication through the same RADIUS servers as in the previous example.

device# configure terminal
device(config)# authentication
device(config-authen)# mac-auth enable
device(config-authen)# mac-auth enable ethernet 2/1/1
device(config-authen)# exit
device(config)# interface ethernet 2/1/1
device(config-if-e1000-2/1/1)# use-radius-server 10.10.10.103
device(config-if-e1000-2/1/1)# use-radius-server 10.10.10.110
device(config-if-e1000-2/1/1)# end