RADIUS general group

You can use a Remote Authentication Dial In User Service (RADIUS) server to secure the following types of access to the switch or router:

  • Telnet access
  • SSH access
  • Web management access
  • Access to the Privileged EXEC level and CONFIG level of the CLI

The following objects provide information on RADIUS authentication and apply to all devices.

Name, OID, and syntax

Access

Description

snRadiusSNMPAccess

brcdIp.1.1.3.12.1.1

Syntax: Integer

Read-only

Indicates if the RADIUS group MIB objects can be accessed by an SNMP manager:

  • disabled(0) - All RADIUS group MIB objects return a “general error”.
  • enabled(1)

Default: enabled(1)

snRadiusEnableTelnetAuth

brcdIp.1.1.3.12.1.2

Syntax: Integer

Read-write

Indicates if Telnet authentication as specified by the RADIUS general group object is enabled:

  • disabled(0)
  • enabled(1)

Default: disabled(0)

snRadiusRetransmit

brcdIp.1.1.3.12.1.3

Syntax: Integer

Read-write

Indicates the number of authentication query retransmissions that can be sent to the RADIUS server.

Valid values: 1 - 5

Default: 2seconds

snRadiusTimeOut

brcdIp.1.1.3.12.1.4

Syntax: Integer

Read-write

Specifies the number of seconds to wait for an authentication reply from the RADIUS server. Each unit is one second.

Valid values: 1 - 60

Default: 3seconds

snRadiusDeadTime

brcdIp.1.1.3.12.1.5

Syntax: Integer

Read-write

Specifies the RADIUS server dead time. Each unit is one minute.

Valid values: 1 - 5

Default: 2seconds

snRadiusKey

brcdIp.1.1.3.12.1.6

Syntax: DisplayString

Read-write

Shows the authentication key as encrypted text.

This object can have up to 64 characters. A write operation can only be done if the SET request uses SNMPv3 with data encrypted using a privacy key.

snRadiusLoginMethod

brcdIp.1.1.3.12.1.7

Syntax: Octet String

Read-write

Shows the sequence of authentication methods for the RADIUS server. Each octet represents a method for authenticating the user at login. Each octet can have one of the following values:

  • enable(1) - Authenticate by the “Enable” password for the command line interface.
  • radius(2) - Authenticate by requesting the RADIUS server.
  • local(3) - Authenticate by local user account table.
  • line(4) - Authenticate by the Telnet password.
  • tacplus(5) - Authenticate by requesting the TACACS Plus server.
  • none(6) - Do not authenticate.
  • tacacs(7) - Authenticate by requesting the TACACS server.

Setting a zero length octet string invalidates all previous authentication methods.

snRadiusEnableMethod

brcdIp.1.1.3.12.1.8

Syntax: Octet String

Read-write

Shows the sequence of authentication methods for the RADIUS server. Each octet represents a method for authenticating the user after login, as the user enters the privilege mode of the command line interface. Each octet can have one of the following values:

  • enable(1) - Authenticate by the “Enable” password for the command line interface.
  • radius(2) - Authenticate by requesting the RADIUS server.
  • local(3) - Authenticate by local user account table.
  • line(4) - Authenticate by the Telnet password.
  • tacplus(5) - Authenticate by requesting the TACACS Plus server.
  • none(6) - Do not authenticate.
  • tacacs(7) - Authenticate by requesting the TACACS server.

Setting a zero length octet string invalidates all previous authentication methods.

snRadiusWebServerMethod

brcdIp.1.1.3.12.1.9

Syntax: Octet String

Read-write

Shows the sequence of authentication methods. Each octet represents a method for authenticating the user who is accessing the Web server. Each octet can have one of the following values:

  • enable(1) - Authenticate by the “Enable” password for the command line interface.
  • radius(2) - Authenticate by requesting the RADIUS server.
  • local(3) - Authenticate by local user account table.
  • line(4) - Authenticate by the Telnet password.
  • tacplus(5) - Authenticate by requesting the TACACS Plus server.
  • none(6) - Do not authenticate.
  • tacacs(7) - Authenticate by requesting the TACACS server.

Setting a zero length octet string invalidates all previous authentication methods.

snRadiusSNMPServerMethod

brcdIp.1.1.3.12.1.10

Syntax: Octet String

Read-write

Shows the sequence of authentication methods. Each octet represents a method to authenticate the user who is accessing the SNMP server. Each octet can have one of the following values:

  • enable(1) - Authenticate by the “Enable” password for the command line interface.
  • radius(2) - Authenticate by requesting the RADIUS server.
  • local(3) - Authenticate by local user account table.
  • line(4) - Authenticate by the Telnet password.
  • tacplus(5) - Authenticate by requesting the TACACS Plus server.
  • none(6) - Do not authenticate.
  • tacacs(7) - Authenticate by requesting the TACACS server.

Setting a zero length octet string invalidates all previous authentication methods.