Enterasys SecureStack C2 C2G170-24 Configuration Manual page 620

Stackable switches
Hide thumbs Also See for SecureStack C2 C2G170-24:
Table of Contents

Advertisement

set radius
realm 
management‐
access | any | 
network‐access
index | all
Defaults
If secret‐value is not specified, none will be applied.
If realm is not specified, the any access realm will be used.
Mode
Switch command, read‐write.
Usage
The SecureStack C2 device allows up to 10 RADIUS accounting servers to be configured, with up 
to two servers active at any given time.
The RADIUS client can only be enabled on the switch once a RADIUS server is online, and its IP 
address(es) has been configured with the same password the RADIUS client will use. 
Examples
This example shows how to enable the RADIUS client for authenticating with RADIUS server 1 at 
IP address 192.168.6.203, UDP authentication port 1812, and an authentication password of 
"pwsecret." As previously noted, the "server secret" password entered here must match that 
already configured as the Read‐Write (rw) password on the RADIUS server
C2(su)->set radius server 1 192.168.6.203 1812 pwsecret
This example shows how to set the RADIUS timeout to 5 seconds:
C2(su)->set radius timeout 5
This example shows how to set RADIUS retries to 10:
C2(su)->set radius retries 10
23-6 Authentication and Authorization Configuration
Realm allows you to define who has to go through the RADIUS server for 
authentication.
management‐access: This means that anyone trying to access the switch 
(Telnet, SSH, Local Management) has to authenticate through the 
RADIUS server.
network‐access: This means that all the users have to authenticate to a 
RADIUS server before they are allowed access to the network.
any: Means that both management‐access and network‐access have 
been enabled.
Note: If the management-access or any access realm has been configured, the
local "admin" account is disabled for access to the switch using the console, Telnet,
or Local Management. Only the network-access realm allows access to the local
"admin" account.
Applies the realm setting to a specific server or to all servers.
Note: If RADIUS is configured with no host IP address on the device, it will use the loopback
interface 0 IP address (if it has been configured) as its source for the NAS-IP attribute. For
information about configuring loopback interfaces, refer to "interface" on page 19-2.
:

Advertisement

Table of Contents
loading

This manual is also suitable for:

C2h124-24Securestack c2

Table of Contents