Specifying Different Servers for Individual AAA Functions

Separate RADIUS servers can be configured and assigned for specific AAA tasks. For example, you can designate one RADIUS server to handle authentication and another RADIUS server to handle accounting. You can specify individual servers for authentication and accounting, but not for authorization. You can set the RADIUS key for each server.

The following example specifies different RADIUS servers for authentication and accounting.

device(config)# radius-server host 10.2.3.4 authentication-only key abc
device(config)# radius-server host 10.2.3.6 accounting-only key ghi

TLS and RADIUS

The following example configures a TLS-encrypted session for the RADIUS server.

device(config)# radius-server host 172.26.67.12 ssl-auth-port 2083 default key omaha

The ssl-auth-port keyword specifies that the server is a RADIUS server running over a TLS-encrypted TCP session. The specified port, 2083, is the default destination TCP port number for RADIUS over TLS. The source port is arbitrary and is not specified. The keyword default indicates that the server can be used for any AAA operation.

TLS-encrypted sessions support both IPv4 and IPv6.

Note: TLS-encrypted TCP sessions are not supported by the management VRF.

Only one auth-port or ssl-auth-port can be specified. If neither is specified, the default auth-port of 1812 is used for authentication, and 1813 is used for accounting with no TLS encryption.

After authentication takes place, the server that performed the authentication is used for authorization and accounting. If the authenticating server cannot perform the requested function, the next server in the configured list of servers is tried. This process repeats until a server that can perform the requested function is found or until every server in the configured list has been tried.