Restrictions For Controlling Switch Access With Radius - Cisco Catalyst 2960-XR Security Configuration Manual

Ios release 15.0 2 ex1
Hide thumbs Also See for Catalyst 2960-XR:
Table of Contents

Advertisement

Restrictions for Controlling Switch Access with RADIUS

• The RADIUS host is normally a multiuser system running RADIUS server software from Cisco (Cisco
• To use the Change-of-Authorization (CoA) interface, a session must already exist on the switch. CoA
• A redundant connection between a switch stack and the RADIUS server is recommended. This is to
For RADIUS operation:
• Users must first successfully complete RADIUS authentication before proceeding to RADIUS
Related Topics
RADIUS and Switch Access, on page 53
RADIUS Operation, on page 54
Restrictions for Controlling Switch Access with RADIUS
This topic covers restrictions for controlling switch access with RADIUS.
General:
• To prevent a lapse in security, you cannot configure RADIUS through a network management application.
RADIUS is not suitable in the following network security situations:
• Multiprotocol access environments. RADIUS does not support AppleTalk Remote Access (ARA),
• Switch-to-switch or router-to-router situations. RADIUS does not provide two-way authentication.
• Networks using a variety of services. RADIUS generally binds a user to one service model.
Related Topics
RADIUS Overview, on page 53
Catalyst 2960-XR Switch Security Configuration Guide, Cisco IOS Release 15.0(2)EX1
52
Secure Access Control Server Version 3.0), Livingston, Merit, Microsoft, or another software provider.
For more information, see the RADIUS server documentation.
can be used to identify a session and enforce a disconnect request. The update affects only the specified
session.
help ensure that the RADIUS server remains accessible in case one of the connected stack members is
removed from the switch stack.
authorization, if it is enabled.
NetBIOS Frame Control Protocol (NBFCP), NetWare Asynchronous Services Interface (NASI), or X.25
PAD connections.
RADIUS can be used to authenticate from one device to a non-Cisco device if the non-Cisco device
requires authentication.
Configuring RADIUS
OL-29434-01

Advertisement

Table of Contents
loading

Table of Contents