Chapter 18
Configuring Switch Security
•
•
About RADIUS
RADIUS is a distributed client/server system that secures networks against unauthorized access. In the
Cisco implementation, RADIUS clients run on Cisco MDS switches and send authentication requests to
a central RADIUS server that contains all user authentication and network service access information.
RADIUS is a fully open protocol, distributed in source code format, that can be modified to work with
any security system currently available on the market.
You can set the RADIUS server address, the RADIUS preshared key, the RADIUS server time-out
interval, iterations of the RADIUS server, define vendor-specific attributes, and display RADIUS server
details.
Configuring RADIUS Authentication
To configure RADIUS authentication from the Fabric Manager, choose Security > Radius from the
menu tree.
To configure RADIUS authentication from the Device Manager, choose Security > Radius (CLI).
Configuring RADIUS Servers
To configure RADIUS servers, perform the following steps:
From the Device Manager, choose Security > Radius and click the Servers tab. You see the Radius
Step 1
dialog box with the Servers tab selected.
To configure RADIUS servers from the Fabric Manager, choose Security > Radius from the menu tree
and click the Servers tab. You see the Radius information in the Information pane.
Step 2
To add a Radius server, click Create on the Device Manager dialog box, or click the Create Row icon
on the Fabric Manager toolbar.
You see the Create Radius Server dialog box.(In Fabric Manager, you can specify the switches to which
the configuration applies.)
Step 3
Complete the fields, and click OK.
Setting the RADIUS Server Address
You can add up to 64 RADIUS servers. RADIUS keys are always stored in encrypted form in persistent
storage. The running configuration also displays encrypted keys. From Fabric Manager, choose
Switches > Security > Radius > Servers to set RADIUS server addresses.
OL-7753-01
Setting Iterations of the RADIUS Server, page 18-6
Defining Vendor-Specific Attributes, page 18-6
Cisco MDS 9000 Fabric Manager Switch Configuration Guide
Configuring RADIUS
18-5