CoA Configuration for Ruckus Switches
- Enable CoA
- Configure Cloudpath as RADIUS Client
- Configure Cloudpath Onboard RADIUS Server as RADIUS Server
Cloudpath RADIUS server listens on port 1812 for RADIUS authentication, and port 1813 for RADIUS accounting.
radius-server host 192.168.xx.xx auth-port 1812 acct-port 1813 default key pass dot1x
Where host is the IP address of the Cloudpath system, 1812 and 1813 are the authentication and accounting ports, respectively, and pass is the shared secret.
If you are configuring an external RADIUS server (as in the command above) you must also configure:
aaa authentication dot1x default radius
This command disables authentication. The client is automatically authenticated by other means, without the device using information supplied by the client.
Example Configuration for an ICX 7250 Switch
authentication auth-default-vlan 1000 dot1x enable dot1x enable ethe 1/1/2 to 1/1/10 dot1x timeout tx-period 10 dot1x timeout quiet-period 10 dot1x timeout supplicant 10 mac-authentication enable mac-authentication enable ethe 1/1/2 to 1/1/10 ! aaa authentication dot1x default radius aaa authentication login default tacacs+ local aaa authorization coa enable aaa accounting exec default start-stop radius aaa accounting dot1x default start-stop radius enable super-user-password ..... hostname ICX7250 ip address 192.168.xx.xx 255.255.252.0 ip dns server-address 192.168.xx.xx 75.75.75.75 8.8.8.8 no ip dhcp-client enable ip default-gateway 192.168.xx.xx ! logging buffered 1000 radius-client coa host 192.168.xx.xx key 2 $b24tb29uLW8= radius-client coa host 192.168.xx.xx key 2 $b24tbw== radius-client coa port 1700 radius-server host 192.168.xx.xx auth-port 1812 acct-port 1813 default key 2 $b24tbw== dot1x radius-server test test ntp server 17.16.xx.xx ! interface ethernet 1/1/2 dot1x port-control auto ! interface ethernet 1/1/24 port-name UPLINK to Cisco Lab Switch ! interface ethernet 1/2/1 disable speed-duplex 1000-full ! interface ethernet 1/2/2 disable speed-duplex 1000-full ! interface ethernet 1/2/3 disable speed-duplex 1000-full ! interface ethernet 1/2/4 disable speed-duplex 1000-full ! interface ethernet 1/2/5 disable speed-duplex 1000-full ! interface ethernet 1/2/6 disable speed-duplex 1000-full ! interface ethernet 1/2/7 disable speed-duplex 1000-full ! interface ethernet 1/2/8 disable speed-duplex 1000-full