Specifying Different Servers for Individual AAA Functions

Separate RADIUS servers can be configured and assigned for specific AAA tasks. For example, you can designate one RADIUS server to handle authentication and another RADIUS server to handle accounting. You can specify individual servers for authentication and accounting, but not for authorization. You can set the RADIUS key for each server.

The following example specifies different RADIUS servers for authentication and accounting.

device(config)# radius-server host 10.2.3.4 authentication-only key abc
device(config)# radius-server host 10.2.3.6 accounting-only key ghi

TLS and RADIUS

TLS-encrypted sessions support 802.1X authentication, MAC authentication, and Web authentication features in IPv4 and IPv6 networks. A previously configured SSL profile must be used for TLS-encrypted sessions for 802.1X authentication, MAC authentication, and Web authentication.

Note: TLS-encrypted TCP sessions are not supported by the management VRF.

Note: As compared to TLS connections on logging host or TACACS+ servers, TLS connections on RADIUS servers require an extra TLS connection for accounting services.

You can use the show ip ssl profile command to verify the SSL profile that has been applied to the device.

device(config)# show ip ssl profile
SSL Profile Information:
***************************

Trustpoint Name    : DEVICE_TRUSTPNT
Remote Domain      : BTC3243M00J.switch-id.ruckuswireless.com
Signature Algorithm: sha256WithRSAEncryption

 Not Before: 2016 Feb 18 19:28:17
 Not After : 2036 Feb 18 19:28:17


Common Name        : RuckusRootCA
Organization       : Ruckus Wireless
Locality           : Sunnyvale
State              : California
Country            : US

Common Name        : RuckusRootCA
Organization       : Ruckus Wireless
Locality           : Sunnyvale
State              : California
Country            : US

-----BEGIN CERTIFICATE-----
MIIFszCCA5ugAwIBAgIIXNVhcWHHz5EwDQYJKoZIhvcNAQELBQAwZzEVMBMGA1UE
AwwMUnVja3VzUm9vdENBMRgwFgYDVQQKDA9SdWNrdXMgV2lyZWxlc3MxEjAQBgNV
BAcMCVN1bm55dmFsZTETMBEGA1UECAwKQ2FsaWZvcm5pYTELMAkGA1UEBhMCVVMw
HhcNMTYwMjE4MTkyODE3WhcNMzYwMjE4MTkyODE3WjBnMRUwEwYDVQQDDAxSdWNr
dXNSb290Q0ExGDAWBgNVBAoMD1J1Y2t1cyBXaXJlbGVzczESMBAGA1UEBwwJU3Vu
bnl2YWxlMRMwEQYDVQQIDApDYWxpZm9ybmlhMQswCQYDVQQGEwJVUzCCAiIwDQYJ
KoZIhvcNAQEBBQADggIPADCCAgoCggIBAMz6iReNwJmMZiobq2Cr39RW90vmso2f
ZEZ6HLFab8ih71L6+mzXoR8OMoQdVtmX5tRW5e/Nk0+6MHk2y1gDw/yIHGc3Ivc0
IHijTx0GFfP5zoKBcpUf9ccNNJnR+rgSWAFCWpDLJotRBf7Gg9smpKJ/Nvdkn8gE
5qnEOyCGwG8MEy6gjjAOckG0IC3h53pI7VekhKAxC4xrwUQD4EqLgVBisL8nCcAl
89ec8hZ78yGAxD/zNN51+UC+nzqP3jSNKe8Yzfv4teBpit/V5ueilw2x/R4Ys9GR
bdiYf8LtfVqDFuj/sLayTJXZNDZKXgnnvZBYP8WEb3fWWkcEknJi8CrtE1uYK1S1
Uo1OocYpJbwFOSZaBZTGal9744N6zXFEFChyYsVCW5Hn4xPfoZrFWWhx+nqhpsc3
HLte6yKG9u+YQWZdwItwaolj+6q6hTe3oleDyfxxgswh8oA7jERCBw8Gk01zL5yS
alx6ctnv417PTw9ZiDIfZqpYOu1rj8MoM9MMpqYjCSbMQthLJqvXfqC2iItt8TyP
I7XAeeR5+M3BqyvInMCz2cdZ464QXt2DyTS+WBB5SYsXD2sMAli7z9QhkIdCUVDR
6pW4G1ewAEFWcG+kzjJRWXDdCXmI4aGs769xvFh5S76+U5t6lC4O1yhZ7TJT9jvx
oQIJ9rjwPpV9AgMBAAGjYzBhMB0GA1UdDgQWBBQV2AsIvxliqdlVa33cp1HpD1Ti
eTAPBgNVHRMBAf8EBTADAQH/MB8GA1UdIwQYMBaAFBXYCwi/GWKp2VVrfdynUekP
VOJ5MA4GA1UdDwEB/wQEAwIBhjANBgkqhkiG9w0BAQsFAAOCAgEADdn/yh/+wNam
RAUG3v17IwC1uoAE5rSO9lc2k5cYIb+iT+HisY1QHRpqiZOhffRv2MZHR+YDuhL8
c/TcWbg4ElmjhgOZcE37kQysF8iHTGRmawGtGGPvjwLsP57t8Wnz3qAvRi2hdc/V
JwJB6FRBu9ESKdt1deQoZ0ccjE71wNWL1dwuovarFMPRLS/u7iLeTMGfIE200Pna
Ztjq2bsf33fVjL1pj10R1lLgStTDUSvL+IdjAaS2LO5PZowtPfTHaRgT7SDmmnWr
EC4SyNmP8PmAkBkHYWkVmgWj/VyDfnHcFEwa8dd5iQVMm+J+2J5oCkg3NZszjAoF
5RzOF+Vcp5FGiPUkNgCt7zg2MbvNLQIDJ8aAIS8GYKjnbZ4pezTw5K/y5f+qK5s/
ZmdOG8zMiCkP70lek3LJK7RSPfHEOEP2Ff89+LflDpW4U4gnUs+qIDaRiBk6NBm8
3FUk3np9agW3QhFgKLhctB2T5qWSfS83pRQFdiL0KcxllDAAHQULwl0i/3lPYwVJ
VvsH5BGYjKLz3MvyGxVUFh4SXKA4GEiELdwSb9PJXhHCQrJ1pHVq+D+PVdGwz2m8
feoGCwF3w3nJVrDGwLOzgm2f01aDHbJMlM1YcgW/ET6VbwjKus5eNlJh7YacbIqw
I7InlLanM0XvBvl6hDoEsV/zq7g/Cjo=
-----END CERTIFICATE-----

After authentication takes place, the server that performed the authentication is used for authorization and accounting. If the authenticating server cannot perform the requested function, the next server in the configured list of servers is tried. This process repeats until a server that can perform the requested function is found or until every server in the configured list has been tried.

The following example shows the default profile available in TPM devices (not user configured).

radius-server host 10.177.131.182 ssl-auth-port 2083 profile DEVICE_PROFILE default key 123qwe dot1x mac-auth web-auth

The following example applies a previously configured SSL profile with a TLS-encrypted session for the RADIUS server.

device(config)# radius-server host 10.177.131.182 ssl-auth-port 2083 profile tls-profile default key radsec dot1x mac-auth web-auth

In the user-configured example, the ssl-auth-port keyword specifies that the server is a RADIUS server running over a TLS-encrypted TCP session. The specified port, 2083, is the default destination TCP port number for RADIUS over TLS. The source port is arbitrary and is not specified. In the example, "tls-profile" is the name of the SSL profile. The keyword default indicates that the server can be used for both authentication and accounting operations. The authentication methods configured are represented by the keywords dot1x, mac-auth, and web-auth.

Only one auth-port or ssl-auth-port can be specified. If neither is specified, the default auth-port of 1812 is used for authentication, and 1813 is used for accounting with no TLS encryption.