radius-server host

Configures the Remote Authentication Dial-In User Service (RADIUS) server.
Syntax
radius-server host { ipv4-address | host-name | ipv6-address } [ auth-port port-num [ acct-port port-num [ { accounting-only | authentication-only | default } [ ssl-auth-port port-num [ accounting-only | authentication-only | default ] [ key key-string [ dot1x | mac-auth | no-login | web-auth ] [ port-only ] ] ] ] ]
no radius-server host { ipv4-address | host-name | ipv6-address } [ auth-port port-num [ acct-port port-num [ { accounting-only | authentication-only | default } [ ssl-auth-port port-num [ accounting-only | authentication-only | default ] [ key key-string [ dot1x | mac-auth | no-login | web-auth ] [ port-only ] ] ] ] ]
Command Default

The RADIUS server host is not configured.

Parameters
ipv4-address
Configures the IPv4 address of the RADIUS server.
host-name
Configures the host name of the RADIUS server.
ipv6-address
Configures the IPv6 address of the RADIUS server.
auth-port port-num
Configures the authentication UDP port. The default value is 1812.
acct-port port-num
Configures the accounting UDP port. The default value is 1813.
accounting-only
Configures the server to be used only for accounting.
authentication-only
Configures the server to be used only for authentication.
default
Configures the server to be used for any AAA operation.
ssl-auth-port port-num
Specifies that the server is a RADIUS server running over a TLS-encrypted TCP session. Only one of auth-port or ssl-auth-port can be specified. If neither is specified, it defaults to the existing default behavior, which uses the default auth-port of 1812 and 1813 for accounting with no TLS encryption. The default destination port number for RADIUS over TLS is TCP/2083.There are no separate ports for authentication, accounting, and dynamic authorization changes. The source port is arbitrary. TLS-encrypted sessions support both IPv4 and IPv6.
accounting-only
Configures the server to be used only for accounting.
authentication-only
Configures the server to be used only for authentication.
default
Configures the server to be used for any AAA operation.
key key-string
Configures the RADIUS key for the server.
dot1x
Configures support for EAP for 802.1X authentication.
mac-auth
Configures the server to be used only for MAC authentication.
no-login
Configures the server not to be used for Telnet, SSH, console, EXEC, or Web-management AAA.
web-auth
Configures the server to be used only for Web authentication.
port-only
Specifies that the server will be used only to authenticate users on ports to which it is mapped.
Modes

Global configuration mode

Usage Guidelines

Use this command to identify a RADIUS server to authenticate access to a RUCKUS device. You can specify up to eight servers. If you add multiple RADIUS authentication servers to the RUCKUS device, the device tries to reach them in the order you add them. To use a RADIUS server to authenticate access to a RUCKUS device, you must identify the server to the RUCKUS device. In a RADIUS configuration, you can designate a server to handle a specific AAA task. For example, you can designate one RADIUS server to handle authorization and another RADIUS server to handle accounting. You can specify individual servers for authentication and accounting, but not for authorization. You can set the RADIUS key for each server.

TLS-encrypted TCP sessions are not supported by management VRF.

The radius-server host command and the radius-server key command must be entered on the same command line to configure the ICX device to authenticate end devices through 802.1x or MAC authentication.

The no form of the command removes the RADIUS sever host configuration.

Examples

The following example configures non-default UDP ports for authorization and accounting.

device(config)# radius-server host 1.2.3.4 auth-port 100 acct-port 200
device(config)# show aaa
***** TACACS server not configured
Radius default key: ...
Radius retries: 3
Radius timeout: 3 seconds
Radius Server:         IP=172.26.67.12 SSL Port=2083 Usage=any 
                   Key=...
                   opens=0 closes=0 timeouts=0 errors=0
                   packets in=0 packets out=0
                   IPv4 Radius Source address: IP=0.0.0.0               IPv6 Radius Source Address:          IP=:: 
Radius Server:         IP=1.2.3.4 Auth Port=100 Acct Port=200 Usage=any 
                   Key=...
                   opens=0 closes=0 timeouts=0 errors=0
                   packets in=0 packets out=0
                   IPv4 Radius Source address: IP=0.0.0.0               IPv6 Radius Source Address:          IP=::

The following example shows how to specify different RADIUS servers for authentication and accounting.

device(config)# radius-server host 10.2.3.4 auth-port 1800 acct-port 1850 default key abc
device(config)# radius-server host 10.2.3.5 auth-port 1800 acct-port 1850 authentication-only key def
device(config)# radius-server host 10.2.3.6 auth-port 1800 acct-port 1850 accounting-only key ghi

The following example shows how to map the 802.1X port to a RADIUS server.

device(config)# radius-server host 10.2.3.4 auth-port 1800 acct-port 1850 default key abc dot1x

The following example shows how to configure a RADIUS server for TLS support.

device(config)# radius-server host 172.26.67.12 ssl-auth-port 2083 default key whatever
device(config)# show aaa
***** TACACS server not configured
Radius default key: ...
Radius retries: 3
Radius timeout: 3 seconds
Radius Server:         IP=172.26.67.12 SSL Port=2083 Usage=any 
                   Key=...
                   opens=0 closes=0 timeouts=0 errors=0
                   packets in=0 packets out=0
                   IPv4 Radius Source address: IP=0.0.0.0               IPv6 Radius Source Address:          IP=::

The following example configures the RADIUS server to be used for both MAC authentication and login features.

device# configure terminal
device(config)# radius-server host 10.26.67.13 auth-port 1812 acct-port 1813 default key ruckus mac-auth

The following example uses the RADIUS server for Flexible authentication modules and login features.

device# configure terminal
device(config)# radius-server host 10.26.67.13 auth-port 1812 acct-port 1813 default key ruckus mac-auth dot1x

The following example uses the RADIUS server for Flexible authentication and excludes the use of the server for login features.

device# configure terminal
device(config)# radius-server host 10.26.67.13 auth-port 1812 acct-port 1813 default key ruckus mac-auth dot1x no-login
History
Release version Command history
08.0.50 This command was updated with the mac-auth and web-auth options.
08.0.80 This command was modified to add the no-login option.