Identifying the RADIUS Server to the RUCKUS Device
To use a RADIUS server to authenticate access to a
RUCKUS device, you must identify the server to the
RUCKUS device using the
radius-server host command.
radius-server
host and key parameters must be entered on the
same command line to configure the ICX device to authenticate end devices through
802.1x or MAC authentication. The key key-string parameter is used to encrypt RADIUS packets before they are sent over the network. The value for the key key-string parameter on the RUCKUS device should match the one configured on the RADIUS server. The key-string can be from 1 through 128 characters in length. It must not contain a space or any of the following characters: #, {, or }.
The following example configures a RADIUS server with IP address 10.157.22.99 and RADIUS key ruckus as a Flexible authentication (dot1x mac-auth) server.
device# configure terminal device(config)# radius-server host 10.157.22.99 acct-port 1813 default key ruckus dot1x mac-auth
The RADIUS status-server packet checks the availability or status of the RADIUS server. This can generate a high number of logs on the server side. To disable these log files, use the radius-server host status-server command. By default, the server status logs are enabled.
Refer to the RUCKUS FastIron Command Reference for more information on the radius-server commands.