Configuring Authentication-method Lists for RADIUS

You can use RADIUS to authenticate Telnet or SSH access and access to the Privileged EXEC and global configuration levels of the CLI. When you configure authentication-method lists for RADIUS, you must create an authentication-method list for Telnet or SSH CLI access and a second separate authentication-method list for access to the Privileged EXEC and global configuration levels of the CLI.

Within the authentication-method list, RADIUS is specified as the primary authentication method, and up to six other authentication methods are specified as alternates. If RADIUS authentication fails, the device tries the alternate authentication methods in the order they appear in the list.

Note: If you configure authentication for Web management access, authentication is performed each time a page is requested from the server. When frames are enabled on the Web Management Interface, the browser sends an HTTP request for each frame. The ICX device authenticates each HTTP request from the browser. To limit authentications to one per page, disable frames on the Web Management Interface.
Note: For examples of how to define authentication-method lists for types of authentication other than RADIUS, refer to Authentication-method Lists.

Perform the following steps to configure authentication-method lists for remote and CLI access.

  1. Enter global configuration mode.
    device# configure terminal
  2. Enable telnet or SSH access.
  3. Enter the aaa authentication login command followed by the desired authentication-method list parameters.
    Note: Refer to Authentication-Method Values for available RADIUS authentication-method list parameters.
    The following example creates an authentication-method list for securing Telnet access to the CLI.
    device# configure terminal
    device(config)# enable telnet authentication
    device(config)# aaa authentication login default radius local
    
    In the example, the default parameter specifies that the methods listed on the same line form the default authentication-method list. The example configures RADIUS as the primary authentication method for securing Telnet access to the CLI. If RADIUS authentication fails due to a server error, local authentication is used instead. If local authentication fails, access is not granted.
  4. Configure authentication methods for access to the Privileged EXEC and global configuration levels of the CLI. Enter the aaa authentication enable command followed by desired parameters.
    The following example configures authentication methods for securing access to the Privileged EXEC level and CONFIG levels of the CLI.
    device(config)# aaa authentication enable default radius local none
    
    The example configures RADIUS as the primary authentication method for securing access to Privileged EXEC and CONFIG levels of the CLI. If RADIUS authentication fails due to a server error, local authentication is used instead. If local authentication fails, no authentication is used, and the device automatically permits access.