RADIUS Security Configuration Example
The following example configures a RADIUS security trustpoint and associated RSA key pair.
device# configure terminal
device(config)# pki import key rsa tls-key pem url flash: test-client.key.pem <--Key file must be imported
before configuring
trustpoint
device(config)# pki trustpoint tls
device(config-pki-trustpoint-tls)# rsakeypair key-label tls-key
device(config-pki-trustpoint-tls)# fingerprint CD:84:56:28:47:63:74:AF:80:80:3A:B1:16:5C:67:C7:04:9B:CB:C9
device(config-pki-trustpoint-tls)# exit
device(config)# pki import tls pem url flash: test-client.cert.pem
device(config)# pki import tls pem url flash: test.rootca.pem
device(config)# pki import key rsa tls-key pem url flash: test-client.key.pem
The following example configures the trustpoint and the remote domain for an SSL profile.
device(config)# ip ssl profile tls_profile device(config-ssl-tls01)# trustpoint tls device(config-ssl-tls01)# remotedomain icx_poc_14.commscope.com device(config-ssl-tls01)# exit
For more information on SSL profiles, refer to Configuring an SSL Profile for Use with RADIUS Server Hosts.
The following example configures the RADIUS server to use the previously configured TLS profile.
device(config)# radius-server host 10.177.171.221 ssl-auth-port 2083 profile tls_profile default key radsec dot1x mac-auth web-auth
TLS and RADIUS in Specifying Different Servers for
Individual AAA Functions. [This topic is in AAA under Technologies and is the one
used in
the security guide with the separate TLS heading. This is not the topic labeled for
FI
use.