RADIUS Authentication and Authorization
How RADIUS Authentication Works
1. Remote administrator connects to the switch and provides user name and
2. Using Authentication/Authorization protocol, the switch sends request to
3. Authentication server checks the request against the user ID database.
4. Using RADIUS protocol, the authentication server instructs the switch to grant or
Configuring RADIUS on the Switch
1. Turn RADIUS authentication on, then configure the Primary and Secondary
2. Configure the RADIUS secret.
78
CN4093 Application Guide for N/OS 8.2
Lenovo N/OS supports the RADIUS (Remote Authentication Dial‐in User Service)
method to authenticate and authorize remote administrators for managing the
switch. This method is based on a client/server model. The Remote Access Server
(RAS)—the switch—is a client to the back‐end database server. A remote user (the
remote administrator) interacts only with the RAS, not the back‐end server and
database.
RADIUS authentication consists of the following components:
A protocol with a frame format that utilizes UDP over IP (based on RFC 2138 and
2866)
A centralized server that stores all the user authorization information
A client, in this case, the switch
The CN4093—acting as the RADIUS client—communicates to the RADIUS server
to authenticate and authorize a remote administrator using the protocol definitions
specified in RFC 2138 and 2866. Transactions between the client and the RADIUS
server are authenticated using a shared key that is not sent over the network. In
addition, the remote administrator passwords are sent encrypted between the
RADIUS client (the switch) and the back‐end RADIUS server.
password.
authentication server.
deny administrative access.
Use the following procedure to configure Radius authentication on your CN4093.
RADIUS servers.
CN4093(config)# radiusserver primaryhost 10.10.1.1
CN4093(config)# radiusserver secondaryhost 10.10.1.2
CN4093(config)# radiusserver primaryhost 10.10.1.1 key <1‐32 character secret>
CN4093(config)# radiusserver secondaryhost 10.10.1.2 key
<1‐32 character secret>
CN4093(config)# radiusserver enable