CoA Configuration for Ruckus Switches

When configuring the switch, Cloudpath is a RADIUS client to the switch, and the Cloudpath onboard RADIUS server is a RADIUS server to the switch, so both must be configured.
  1. Enable CoA
    aaa authorization coa enable
  2. Configure Cloudpath as RADIUS Client
    radius-client coa host 192.168.xx.xx key pass
    Where host is the IP address of the Cloudpath system and pass is the CoA shared secret.
  3. Configure Cloudpath Onboard RADIUS Server as RADIUS Server
    Cloudpath RADIUS server listens on port 1812 for RADIUS authentication, and port 1813 for RADIUS accounting.
    radius-server host 192.168.xx.xx auth-port 1812 acct-port 1813 default key pass dot1x

    Where host is the IP address of the Cloudpath system, 1812 and 1813 are the authentication and accounting ports, respectively, and pass is the shared secret.

    If you are configuring an external RADIUS server (as in the command above) you must also configure:

    aaa authentication dot1x default radius

    This command disables authentication. The client is automatically authenticated by other means, without the device using information supplied by the client.

Example Configuration for an ICX 7250 Switch

authentication
auth-default-vlan 1000 dot1x enable
dot1x enable ethe 1/1/2 to 1/1/10 dot1x timeout tx-period 10
dot1x timeout quiet-period 10 dot1x timeout supplicant 10 mac-authentication enable
mac-authentication enable ethe 1/1/2 to 1/1/10
!
aaa authentication dot1x default radius
aaa authentication login default tacacs+ local aaa authorization coa enable
aaa accounting exec default start-stop radius aaa accounting dot1x default start-stop radius enable super-user-password .....
hostname ICX7250
ip address 192.168.xx.xx 255.255.252.0
ip dns server-address 192.168.xx.xx 75.75.75.75 8.8.8.8 no ip dhcp-client enable
ip default-gateway 192.168.xx.xx
!
logging buffered 1000
radius-client coa host 192.168.xx.xx key 2 $b24tb29uLW8= radius-client coa host 192.168.xx.xx key 2 $b24tbw== radius-client coa port 1700
radius-server host 192.168.xx.xx auth-port 1812 acct-port 1813 default key 2
$b24tbw== dot1x
radius-server test test
ntp
server 17.16.xx.xx
!
interface ethernet 1/1/2 dot1x port-control auto
!
interface ethernet 1/1/24
port-name UPLINK to Cisco Lab Switch
!
interface ethernet 1/2/1 disable
speed-duplex 1000-full
!
interface ethernet 1/2/2 disable
speed-duplex 1000-full
!
interface ethernet 1/2/3 disable
speed-duplex 1000-full
!
interface ethernet 1/2/4 disable
speed-duplex 1000-full
!
interface ethernet 1/2/5 disable
speed-duplex 1000-full
!
interface ethernet 1/2/6 disable
speed-duplex 1000-full
!
interface ethernet 1/2/7 disable
speed-duplex 1000-full
!
interface ethernet 1/2/8 disable
speed-duplex 1000-full