Specifying Different Servers for Individual AAA Functions
Separate RADIUS servers can be configured and assigned for specific AAA tasks. For example, you can designate one RADIUS server to handle authentication and another RADIUS server to handle accounting. You can specify individual servers for authentication and accounting, but not for authorization. You can set the RADIUS key for each server.
The following example specifies different RADIUS servers for authentication and accounting.
device(config)#radius-server host 10.2.3.4 authentication-only key abc device(config)#radius-server host 10.2.3.6 accounting-only key ghi
TLS and RADIUS
TLS-encrypted sessions support 802.1X authentication, MAC authentication, and Web authentication features in IPv4 and IPv6 networks. A previously configured SSL profile must be used for TLS-encrypted sessions for 802.1X authentication, MAC authentication, and Web authentication.
You can use the show ip ssl profile command to verify the SSL
profile that has been applied to the
device.
device(config)# show ip ssl profile SSL Profile Information: *************************** Trustpoint Name : DEVICE_TRUSTPNT Remote Domain : BTC3243M00J.switch-id.ruckuswireless.com Signature Algorithm: sha256WithRSAEncryption Not Before: 2016 Feb 18 19:28:17 Not After : 2036 Feb 18 19:28:17 Common Name : RuckusRootCA Organization : Ruckus Wireless Locality : Sunnyvale State : California Country : US Common Name : RuckusRootCA Organization : Ruckus Wireless Locality : Sunnyvale State : California Country : US -----BEGIN CERTIFICATE----- MIIFszCCA5ugAwIBAgIIXNVhcWHHz5EwDQYJKoZIhvcNAQELBQAwZzEVMBMGA1UE AwwMUnVja3VzUm9vdENBMRgwFgYDVQQKDA9SdWNrdXMgV2lyZWxlc3MxEjAQBgNV BAcMCVN1bm55dmFsZTETMBEGA1UECAwKQ2FsaWZvcm5pYTELMAkGA1UEBhMCVVMw HhcNMTYwMjE4MTkyODE3WhcNMzYwMjE4MTkyODE3WjBnMRUwEwYDVQQDDAxSdWNr dXNSb290Q0ExGDAWBgNVBAoMD1J1Y2t1cyBXaXJlbGVzczESMBAGA1UEBwwJU3Vu bnl2YWxlMRMwEQYDVQQIDApDYWxpZm9ybmlhMQswCQYDVQQGEwJVUzCCAiIwDQYJ KoZIhvcNAQEBBQADggIPADCCAgoCggIBAMz6iReNwJmMZiobq2Cr39RW90vmso2f ZEZ6HLFab8ih71L6+mzXoR8OMoQdVtmX5tRW5e/Nk0+6MHk2y1gDw/yIHGc3Ivc0 IHijTx0GFfP5zoKBcpUf9ccNNJnR+rgSWAFCWpDLJotRBf7Gg9smpKJ/Nvdkn8gE 5qnEOyCGwG8MEy6gjjAOckG0IC3h53pI7VekhKAxC4xrwUQD4EqLgVBisL8nCcAl 89ec8hZ78yGAxD/zNN51+UC+nzqP3jSNKe8Yzfv4teBpit/V5ueilw2x/R4Ys9GR bdiYf8LtfVqDFuj/sLayTJXZNDZKXgnnvZBYP8WEb3fWWkcEknJi8CrtE1uYK1S1 Uo1OocYpJbwFOSZaBZTGal9744N6zXFEFChyYsVCW5Hn4xPfoZrFWWhx+nqhpsc3 HLte6yKG9u+YQWZdwItwaolj+6q6hTe3oleDyfxxgswh8oA7jERCBw8Gk01zL5yS alx6ctnv417PTw9ZiDIfZqpYOu1rj8MoM9MMpqYjCSbMQthLJqvXfqC2iItt8TyP I7XAeeR5+M3BqyvInMCz2cdZ464QXt2DyTS+WBB5SYsXD2sMAli7z9QhkIdCUVDR 6pW4G1ewAEFWcG+kzjJRWXDdCXmI4aGs769xvFh5S76+U5t6lC4O1yhZ7TJT9jvx oQIJ9rjwPpV9AgMBAAGjYzBhMB0GA1UdDgQWBBQV2AsIvxliqdlVa33cp1HpD1Ti eTAPBgNVHRMBAf8EBTADAQH/MB8GA1UdIwQYMBaAFBXYCwi/GWKp2VVrfdynUekP VOJ5MA4GA1UdDwEB/wQEAwIBhjANBgkqhkiG9w0BAQsFAAOCAgEADdn/yh/+wNam RAUG3v17IwC1uoAE5rSO9lc2k5cYIb+iT+HisY1QHRpqiZOhffRv2MZHR+YDuhL8 c/TcWbg4ElmjhgOZcE37kQysF8iHTGRmawGtGGPvjwLsP57t8Wnz3qAvRi2hdc/V JwJB6FRBu9ESKdt1deQoZ0ccjE71wNWL1dwuovarFMPRLS/u7iLeTMGfIE200Pna Ztjq2bsf33fVjL1pj10R1lLgStTDUSvL+IdjAaS2LO5PZowtPfTHaRgT7SDmmnWr EC4SyNmP8PmAkBkHYWkVmgWj/VyDfnHcFEwa8dd5iQVMm+J+2J5oCkg3NZszjAoF 5RzOF+Vcp5FGiPUkNgCt7zg2MbvNLQIDJ8aAIS8GYKjnbZ4pezTw5K/y5f+qK5s/ ZmdOG8zMiCkP70lek3LJK7RSPfHEOEP2Ff89+LflDpW4U4gnUs+qIDaRiBk6NBm8 3FUk3np9agW3QhFgKLhctB2T5qWSfS83pRQFdiL0KcxllDAAHQULwl0i/3lPYwVJ VvsH5BGYjKLz3MvyGxVUFh4SXKA4GEiELdwSb9PJXhHCQrJ1pHVq+D+PVdGwz2m8 feoGCwF3w3nJVrDGwLOzgm2f01aDHbJMlM1YcgW/ET6VbwjKus5eNlJh7YacbIqw I7InlLanM0XvBvl6hDoEsV/zq7g/Cjo= -----END CERTIFICATE-----
After authentication takes place, the server that performed the authentication is used for authorization and accounting. If the authenticating server cannot perform the requested function, the next server in the configured list of servers is tried. This process repeats until a server that can perform the requested function is found or until every server in the configured list has been tried.
The following example shows the default profile available in TPM devices (not user configured).
radius-server host 10.177.131.182 ssl-auth-port 2083 profile DEVICE_PROFILE default key 123qwe dot1x mac-auth web-auth
The following example applies a previously configured SSL profile with a TLS-encrypted session for the RADIUS server.
device(config)# radius-server host 10.177.131.182 ssl-auth-port 2083 profile tls-profile default key radsec dot1x mac-auth web-auth
In the user-configured example, the
ssl-auth-port
keyword specifies that the server is a RADIUS server running over a TLS-encrypted
TCP session. The specified port, 2083, is the default destination TCP port number
for RADIUS over TLS. The source port is arbitrary and is not specified. In the
example, "tls-profile" is the name of the SSL profile. The keyword
default indicates that the server can be used for both
authentication and accounting operations. The authentication methods configured
are
represented by the keywords dot1x, mac-auth, and web-auth.
Only one auth-port or ssl-auth-port can be specified. If neither is specified, the default auth-port of 1812 is used for authentication, and 1813 is used for accounting with no TLS encryption.