D-Link DI-1750 Reference Manual page 351

Hide thumbs Also See for DI-1750:
Table of Contents

Advertisement

♦ REJECT:The user is not authenticated and is prompted to reenter the username and password, or
access is denied.
♦ CHALLENGE:A challenge is issued by the RADIUS server. The challenge collects additional data
from the user.
The ACCEPT or REJECT response is bundled with additional data that is used for EXEC or
NETWORK authorization. You must first complete RADIUS authentication before using RADIUS
authorization. The additional data included with the ACCEPT or REJECT packets consists of the
following:
Services that the user can access, including Telnet, rlogin, and PPP, Serial Line Internet Protocol
(SLIP), or EXEC services.
Connection parameters, including the host or client IP address, access list, and user timeouts.
2. RADIUS Configuration Steps
To configure RADIUS on the Router or access server, you must perform the following tasks:
Use aaa authentication global configuration command to define method lists for RADIUS authentication.
For more information about using the aaa authentication command, refer to the "Configuring
Authentication" chapter.
Use line and interface commands to enable the defined method lists to be used. For more information,
refer to the "Configuring Authentication" chapter.
8.2.2 Configure Router to RADIUS Server Communication
The RADIUS host is normally a multiuser system running RADIUS server software from Livingston,
Merit, Microsoft, or another software provider. A RADIUS server and a router use a shared secret key to
encrypt passwords and exchange responses. Use the radius server command to specify the RADIUS
server and use radius key to specify the shared key. use the following commands in global
configuration directory:
radius server ip-address [auth-port
port-number][acct-port portnumber]
radius key string
Example: 1. To specify RADIUS server:
[DEFAULT@Router /config/]#radius
......
(05)server
(06)timeout
(07)vsa
(08)test
Please Input the code of command to be excute(0-8): 5
(00)A.B.C.D
Please Input the code of command to be excute(0-0): 0
Please input a IP Address:192.168.0.1 (Input IP of the RADIUS server)
(00)acct-port
(01)auth-port
(02)<cr>
Please Input the code of command to be excute(0-2): 1
(00)<0-65536>
Please Input the code of command to be excute(0-0): 0
Command
Specify a RADIUS server
Time to wait for a RADIUS server to reply
Vendor specific attribute configuration
Radius test
IP address of RADIUS server
UDP port for RADIUS accounting server (default is 1646)
UDP port for RADIUS authentication server (default is 1645)
Port number
Model Name
Purpose
Specify the IP address of the remote
RADIUS
server
host
authentication
and
destination port numbers.
Specify the shared secret key used
between the router and the RADIUS
server.
- 349 -
and
assign
accounting

Advertisement

Table of Contents
loading

This manual is also suitable for:

Di-2621Di-2630Di-3660

Table of Contents