RADIUS general group

You can use a Remote Authentication Dial In User Service (RADIUS) server to secure the following types of access to the switch or router:

  • Telnet access
  • SSH access
  • Web management access
  • Access to the Privileged EXEC level and CONFIG level of the CLI

The following objects provide information on RADIUS authentication and apply to all devices.

Name, OID, and syntax

Access

Description

snRadiusSNMPAccess

1.3.6.1.4.1.1991.1.1.3.12.1.1

Syntax: Integer

Read-only

Indicates if the RADIUS group MIB objects can be accessed by an SNMP manager:

  • disabled(0) - All RADIUS group MIB objects return a “general error”.
  • enabled(1)

Default: enabled(1)

snRadiusEnableTelnetAuth

1.3.6.1.4.1.1991.1.1.3.12.1.2

Syntax: Integer

Read-write

Indicates if Telnet authentication as specified by the RADIUS general group object is enabled:

  • disabled(0)
  • enabled(1)

Default: disabled(0)

snRadiusRetransmit

1.3.6.1.4.1.1991.1.1.3.12.1.3

Syntax: Integer

Read-write

Indicates the number of authentication query retransmissions that can be sent to the RADIUS server.

Valid values: 1 - 5

Default: 2 seconds

snRadiusTimeOut

1.3.6.1.4.1.1991.1.1.3.12.1.4

Syntax: Integer

Read-write

Specifies the number of seconds to wait for an authentication reply from the RADIUS server. Unit of measure is one second.

Valid values: 1 - 60

Default: 3 seconds

snRadiusDeadTime

1.3.6.1.4.1.1991.1.1.3.12.1.5

Syntax: Integer

Read-write

Specifies the RADIUS server dead time. Unit of measure is one minute.

Valid values: 1 - 5

Default: 2 seconds

snRadiusKey

1.3.6.1.4.1.1991.1.1.3.12.1.6

Syntax: DisplayString

Read-write

Shows the authentication key as encrypted text.

This object can have up to 64 characters. A write operation can only be done if the SET request uses SNMPv3 with data encrypted using a privacy key.

snRadiusLoginMethod

1.3.6.1.4.1.1991.1.1.3.12.1.7

Syntax: Octet String

Read-write

Shows the sequence of authentication methods for the RADIUS server. Each octet represents a method for authenticating the user at login. Each octet can have one of the following values:

  • enable(1) - Authenticate by the “Enable” password for the command line interface.
  • radius(2) - Authenticate by requesting the RADIUS server.
  • local(3) - Authenticate by local user account table.
  • line(4) - Authenticate by the Telnet password.
  • tacplus(5) - Authenticate by requesting the TACACS Plus server.
  • none(6) - Do not authenticate.
  • tacacs(7) - Authenticate by requesting the TACACS server.

Setting a zero length octet string invalidates all previous authentication methods.

snRadiusEnableMethod

1.3.6.1.4.1.1991.1.1.3.12.1.8

Syntax: Octet String

Read-write

Shows the sequence of authentication methods for the RADIUS server. Each octet represents a method for authenticating the user after login, as the user enters the privilege mode of the command line interface. Each octet can have one of the following values:

  • enable(1) - Authenticate by the “Enable” password for the command line interface.
  • radius(2) - Authenticate by requesting the RADIUS server.
  • local(3) - Authenticate by local user account table.
  • line(4) - Authenticate by the Telnet password.
  • tacplus(5) - Authenticate by requesting the TACACS Plus server.
  • none(6) - Do not authenticate.
  • tacacs(7) - Authenticate by requesting the TACACS server.

Setting a zero length octet string invalidates all previous authentication methods.

snRadiusWebServerMethod

1.3.6.1.4.1.1991.1.1.3.12.1.9

Syntax: Octet String

Read-write

Shows the sequence of authentication methods. Each octet represents a method for authenticating the user who is accessing the Web server. Each octet can have one of the following values:

  • enable(1) - Authenticate by the “Enable” password for the command line interface.
  • radius(2) - Authenticate by requesting the RADIUS server.
  • local(3) - Authenticate by local user account table.
  • line(4) - Authenticate by the Telnet password.
  • tacplus(5) - Authenticate by requesting the TACACS Plus server.
  • none(6) - Do not authenticate.
  • tacacs(7) - Authenticate by requesting the TACACS server.

Setting a zero length octet string invalidates all previous authentication methods.

snRadiusSNMPServerMethod

1.3.6.1.4.1.1991.1.1.3.12.1.10

Syntax: Octet String

Read-write

Shows the sequence of authentication methods. Each octet represents a method to authenticate the user who is accessing the SNMP server. Each octet can have one of the following values:

  • enable(1) - Authenticate by the “Enable” password for the command line interface.
  • radius(2) - Authenticate by requesting the RADIUS server.
  • local(3) - Authenticate by local user account table.
  • line(4) - Authenticate by the Telnet password.
  • tacplus(5) - Authenticate by requesting the TACACS Plus server.
  • none(6) - Do not authenticate.
  • tacacs(7) - Authenticate by requesting the TACACS server.

Setting a zero length octet string invalidates all previous authentication methods.