RADIUS Security Configuration Example

The following example configures a RADIUS security trustpoint and associated RSA key pair.

device# configure terminal
device(config)# pki import key rsa tls-key pem url flash: test-client.key.pem  <--Key file must be imported
                                                                                  before configuring 
                                                                                  trustpoint 
device(config)# pki trustpoint tls
device(config-pki-trustpoint-tls)# rsakeypair key-label tls-key
device(config-pki-trustpoint-tls)# fingerprint CD:84:56:28:47:63:74:AF:80:80:3A:B1:16:5C:67:C7:04:9B:CB:C9
device(config-pki-trustpoint-tls)# exit
device(config)# pki import tls pem url flash: test-client.cert.pem
device(config)# pki import tls pem url flash: test.rootca.pem
device(config)# pki import key rsa tls-key pem url flash: test-client.key.pem 

The following example configures the trustpoint and the remote domain for an SSL profile.

device(config)# ip ssl profile tls_profile 
device(config-ssl-tls01)# trustpoint tls
device(config-ssl-tls01)# remotedomain icx_poc_14.commscope.com
device(config-ssl-tls01)# exit

For more information on SSL profiles, refer to Configuring an SSL Profile for Use with RADIUS Server Hosts.

The following example configures the RADIUS server to use the previously configured TLS profile.

device(config)# radius-server host 10.177.171.221 ssl-auth-port 2083 profile tls_profile default key radsec dot1x mac-auth web-auth

TLS and RADIUS in Specifying Different Servers for Individual AAA Functions. [This topic is in AAA under Technologies and is the one used in the security guide with the separate TLS heading. This is not the topic labeled for FI use.