Configuring Switch AAA Servers

To add and manage Authentication, Authorization, and Accounting (AAA) servers that the controller can use for authentication, follow these steps.

  1. Select Network > Wired > Switches The Switches window is displayed.
  2. Select a Domain > Switch Group and scroll down to view the details.
  3. In the Common Configuration tab, click the Configure icon to display the Common Configuration dialog box.
  4. Click the AAA tab.
  5. Expand the AAA Servers section.
  6. Click the [+Create] icon.
    The Create AAA Server page is displayed.
  7. Enter the AAA server name.
  8. For Type, select RADIUS, TACACS+ or Local User type of AAA server to authenticate user.

    Creating a Switch AAA Server with Type as RADIUS

    Creating a Switch AAA Server with Type as RADIUS
  9. IP Address: Enter the IP address of the AAA server.
  10. Auth. Port: Enter the authentication port that the server is using.
    Note: The default port number is 1812. If you need to enter any other value for the port number, it must be within the range of 0 to 65535.
  11. Acct. Port: Enter the accounting port that the server is using.
    Note: The default port number is 1813. If you need to enter any other value for the port number, it must be within the range of 0 to 65535.
  12. Shared Secret: Enter the shared secret.
  13. Confirm Shared Secret: Re-enter the shared secret to confirm.
  14. Purpose: When Type=RADIUS, select the purpose for the RADIUS AAA server being created. Values are Default, Authentication and Accounting from the list.

    Note: Starting with 7.0 release, you can set up multiple RADIUS servers with different options such as Authentication and Accounting. In earlier releases, the controller could only configure a RADIUS server for a switch with the Default option.

    Note: The switch supports this setting on FastIron release 08.0.90 and later versions.

    When Type=TACACS+, select the purpose for the TACACS+ AAA server being created. Values are Default, Authentication, Authorization, and Accounting. When Type = Local User, select the privilege for the Local User server being created. Values are Port Config , Read Only and Read Write.

  15. Click OK.
    You can subsequently edit or delete a AAA server by selecting the server from the list in the AAA Servers section and selecting Configure or Delete, respectively.
    Note:
    SCG-103623
    The ICX switch fails to delete the TACACS+ and RADIUS AAA servers when pushed from SmartZone or Virtual SmartZone if SNMP query is disabled in the switch or if the switch is pre-configured before joining SmartZone or Virtual SmartZone.