Configuring Detection of Dead RADIUS Servers

The RUCKUS ICX device tries to use the RADIUS servers in the order they are added to the device configuration. If one RADIUS server times out (does not respond), the RUCKUS ICX device tries the next one in the list. Servers are tried in the same sequence each time there is a request, and if multiple servers are unavailable or not responding, authentication delay results.

The RADIUS servers that are unavailable or that have stopped responding can be detected and marked as dead servers using the radius-server test command. To test the availability of the server, an Access-Request message is sent to the RADIUS server using a nonexistent username; that is, a username that is not configured on the server, so that the server responds with an Access-Reject message if the server is available. If the RUCKUS ICX device does not receive a response from a RADIUS server within a specified time limit and number of retries, the RADIUS server is marked as dead.

When dead RADIUS server detection is configured, all configured RADIUS servers are monitored on a regular basis from system startup. When a RADIUS server times out (does not respond), it is marked as a dead server. The change in status of a RADIUS server tagged for 802.1x or MAC authentication is recorded and broadcast to all units in a stack because 802.1x authentication and MAC authentication are performed locally on all units.

Complete the following steps to configure dead RADIUS server detection.

  1. Enter global configuration mode.
    device# configure terminal
  2. (Optional) Adjust the time limit for server responses and maximum retries before the RADIUS server is declared dead.
    Note: For more information, refer to Setting RADIUS Parameters.
    device(config)# radius-server timeout 4
    device(config)# radius-server retransmit 5
    
  3. Enter the radius-server test command followed by the name of a non-existent user.
    device(config)# radius-server test batman
  4. (Optional) Adjust the test message interval. Enter the radius-server dead-time command followed by the desired value, from 1 through 5 minutes. The default dead-time for RADIUS is 2 minutes.
    device(config)# radius-server dead-time 2

The following example configures dead server detection.

device# configure terminal
device(config)# radius-server test batman 
device(config)# radius-server dead-time  3 
device(config)# exit
device# show radius server
----------------------------------------------------------------------------
Server                      Type      Opens     Closes   Timeouts   Status  
----------------------------------------------------------------------------
10.20.226.113                any        471        247          1   active 
10.20.226.114                any        471        247          1   dead