Configuring A Radius Server Failover - Cisco WS-C6506 Software Manual

Catalyst 6500 series switch
Hide thumbs Also See for WS-C6506:
Table of Contents

Advertisement

Configuring 802.1X Authentication on the Switch

Configuring a RADIUS Server Failover

Before software release 8.4(1), when the active RADIUS server went down or was unreachable, the
802.1X authentication timed out before the backup RADIUS server could become active. With software
release 8.4(1) and later releases, some RADIUS server timer values are now configurable and the show
radius command has been enhanced to show the active RADIUS server.
Enter the following commands to prevent a RADIUS server failover:
Ener the show radius command to display the RADIUS server configuration and to show which
RADIUS server is active as follows:
Console> (enable) show radius
Active RADIUS Server:
RADIUS Deadtime:
RADIUS Key:
RADIUS Retransmit:
RADIUS Timeout:
Framed-Ip Address Transmit:
RADIUS-Server
-------------------------------- ------- --------- --------- -------------------
81.81.81.20
10.6.89.200
10.6.98.35
Console> (enable)
Catalyst 6500 Series Switch Software Configuration Guide—Release 8.7
40-40
set dot1x max-req—Specifies the maximum number of times that the state machine retransmits an
EAP-Request frame to the supplicant before it times out the authentication session; the valid values
are from 1 to 10. The default is 2. An example is as follows:
Console> (enable) set dot1x max-req 8
dot1x max-req set to 8.
Console> (enable)
set dot1x server-timeout—Specifies the time constant for the retransmission of packets by the
back-end authenticator to the authentication server; the valid values are from 1 to 65535 seconds.
When the authentication server does not notify the back-end authenticator that it received specific
packets, the back-end authenticator waits a period of time (set by entering the server-timeout
seconds parameter), and then retransmits the packets. The default is 30. An example is as follows:
Console> (enable) set dot1x server-timeout 100
dot1x server-timeout set to 100 seconds.
Console> (enable)
81.81.81.20
1 minutes
cisco
2
5 seconds
Disabled
Status
Auth-port Acct-port Resolved IP Address
primary 1812
1813
1812
1813
1812
1813
Chapter 40
Configuring 802.1X Authentication
OL-8978-04

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

Catalyst 6506Catalyst 6509Catalyst 6513

Table of Contents