Configuring a RADIUS Server Host for NDcPP
- Configure a radius-server host for user authentication by specifying its local or
remote IP address, the remote port of the RADIUS server, and the name of the previously
configured SSL profile to be used.
device(config)# radius-server host < ip-address | server-name > ssl-auth-port < port-number > profile < profile-name > authentication key < radius-key >
The following syntax statement includes only information relevant to encryption.Syntax:radius-server{ host { ip-address | server-name } ssl-auth-port port-number profile profile-name authentication key radius-key }When the user tries to log into the FastIron device, he is first authenticated by the radius server. Before the FastIron device sends out the Radius request to the server, the FastIron device establishes a secure TLS tunnel.
During the handshake with the server, the FastIron device receives the server certificate, and it is validated by the CA server through the PKI infrastructure.
If validation is successful, the handshake continues to look for the client certificate. If the server has requested the client certificate, the FastIron device sends the client certificate, and the server validates it using Verify protocol logic.
If the client and server certificate validations are successful, a TLS tunnel is established, and the Radius authentication request and response are sent over the secure and trusted tunnel.
If TLS tunnel establishment fails, the FastIron device attempts to establish the tunnel and authenticate the user when the user tries to log in again.
The following example configures a RADIUS server host with an IP address of 10.20.158.104. The SSL authentication port is 8001. The profile used is tls03, and the RADIUS authentication key is tesT123$$.
device(config)# radius-server host 10.20.158.104 ssl-auth-port 8001 profile tls03 authentication key tesT123$$