radius-server host
radius-server host
{
ipv4-address
|
host-name
|
ipv6-address
}
[
auth-port
port-num
[
acct-port
port-num
[
{
accounting-only
|
authentication-only
|
default
}
[
ssl-auth-port
port-num
[
accounting-only
|
authentication-only
|
default
]
[
key
key-string
[
dot1x
|
mac-auth
|
no-login
|
web-auth
]
[
port-only
]
]
]
]
]
no radius-server host
{
ipv4-address
|
host-name
|
ipv6-address
}
[
auth-port
port-num
[
acct-port
port-num
[
{
accounting-only
|
authentication-only
|
default
}
[
ssl-auth-port
port-num
[
accounting-only
|
authentication-only
|
default
]
[
key
key-string
[
dot1x
|
mac-auth
|
no-login
|
web-auth
]
[
port-only
]
]
]
]
]
The RADIUS server host is not configured.
- ssl-auth-port port-num
- Specifies that the server is a RADIUS server running over a TLS-encrypted TCP session. Only one of auth-port or ssl-auth-port can be specified. If neither is specified, it defaults to the existing default behavior, which uses the default auth-port of 1812 and 1813 for accounting with no TLS encryption. The default destination port number for RADIUS over TLS is TCP/2083.There are no separate ports for authentication, accounting, and dynamic authorization changes. The source port is arbitrary. TLS-encrypted sessions support both IPv4 and IPv6.
- no-login
- Configures the server not to be used for Telnet, SSH, console, EXEC, or Web-management AAA.
Global configuration mode
Use this command to identify a RADIUS server to authenticate access to a RUCKUS device. You can specify up to eight servers. If you add multiple RADIUS authentication servers to the RUCKUS device, the device tries to reach them in the order you add them. To use a RADIUS server to authenticate access to a RUCKUS device, you must identify the server to the RUCKUS device. In a RADIUS configuration, you can designate a server to handle a specific AAA task. For example, you can designate one RADIUS server to handle authorization and another RADIUS server to handle accounting. You can specify individual servers for authentication and accounting, but not for authorization. You can set the RADIUS key for each server.
TLS-encrypted TCP sessions are not supported by management VRF.
The
radius-server host command and the
radius-server key command must be entered on the same command line to configure the ICX device to authenticate
end devices through 802.1x or MAC authentication.
The
no form of the command removes the RADIUS sever host configuration.
The following example configures non-default UDP ports for authorization and accounting.
device(config)# radius-server host 1.2.3.4 auth-port 100 acct-port 200
device(config)# show aaa
***** TACACS server not configured
Radius default key: ...
Radius retries: 3
Radius timeout: 3 seconds
Radius Server: IP=172.26.67.12 SSL Port=2083 Usage=any
Key=...
opens=0 closes=0 timeouts=0 errors=0
packets in=0 packets out=0
IPv4 Radius Source address: IP=0.0.0.0 IPv6 Radius Source Address: IP=::
Radius Server: IP=1.2.3.4 Auth Port=100 Acct Port=200 Usage=any
Key=...
opens=0 closes=0 timeouts=0 errors=0
packets in=0 packets out=0
IPv4 Radius Source address: IP=0.0.0.0 IPv6 Radius Source Address: IP=::
The following example shows how to specify different RADIUS servers for authentication and accounting.
device(config)# radius-server host 10.2.3.4 auth-port 1800 acct-port 1850 default key abc device(config)# radius-server host 10.2.3.5 auth-port 1800 acct-port 1850 authentication-only key def device(config)# radius-server host 10.2.3.6 auth-port 1800 acct-port 1850 accounting-only key ghi
The following example shows how to map the 802.1X port to a RADIUS server.
device(config)# radius-server host 10.2.3.4 auth-port 1800 acct-port 1850 default key abc dot1x
The following example shows how to configure a RADIUS server for TLS support.
device(config)# radius-server host 172.26.67.12 ssl-auth-port 2083 default key whatever
device(config)# show aaa
***** TACACS server not configured
Radius default key: ...
Radius retries: 3
Radius timeout: 3 seconds
Radius Server: IP=172.26.67.12 SSL Port=2083 Usage=any
Key=...
opens=0 closes=0 timeouts=0 errors=0
packets in=0 packets out=0
IPv4 Radius Source address: IP=0.0.0.0 IPv6 Radius Source Address: IP=::
The following example configures the RADIUS server to be used for both MAC authentication and login features.
device# configure terminal device(config)# radius-server host 10.26.67.13 auth-port 1812 acct-port 1813 default key ruckus mac-auth
The following example uses the RADIUS server for Flexible authentication modules and login features.
device# configure terminal device(config)# radius-server host 10.26.67.13 auth-port 1812 acct-port 1813 default key ruckus mac-auth dot1x