Prerequisites For Radius; Configuring Radius Servers - Cisco nexus 5000 series Cli Configuration Manual

Hide thumbs Also See for nexus 5000 series:
Table of Contents

Advertisement

Prerequisites for RADIUS

S e n d f e e d b a c k t o n x 5 0 0 0 - d o c f e e d b a c k @ c i s c o . c o m
When you use RADIUS servers for authentication on a Nexus 5000 Series switch, the RADIUS protocol
directs the RADIUS server to return user attributes, such as authorization information, along with
authentication results. This authorization information is specified through VSAs.
The following VSA protocol options are supported by the Nexus 5000 Series switch:
The Nexus 5000 Series switch supports the following attributes:
Prerequisites for RADIUS
RADIUS has the following prerequisites:
Guidelines and Limitations
RADIUS has the following guidelines and limitations:

Configuring RADIUS Servers

To configure RADIUS servers, perform this task:
Step 1
Establish the RADIUS server connections to the Nexus 5000 Series switch.
See the
Configure the preshared secret keys for the RADIUS servers.
Step 2
See the
If needed, configure RADIUS server groups with subsets of the RADIUS servers for AAA
Step 3
authentication methods.
See the
"Configuring AAA" section on page
If needed, configure any of the following optional parameters:
Step 4
Cisco Nexus 5000 Series Switch CLI Software Configuration Guide
1-4
Shell— Used in access-accept packets to provide user profile information.
Accounting— Used in accounting-request packets. If a value contains any white spaces, you should
enclose the value within double quotation marks.
roles—Lists all the roles to which the user belongs. The value field is a string that lists the role
names delimited by white space.
accountinginfo—Stores accounting information in addition to the attributes covered by a standard
RADIUS accounting protocol. This attribute is sent only in the VSA portion of the Account-Request
frames from the RADIUS client on the switch. It can be used only with the accounting protocol data
units (PDUs).
Obtain IPv4 or IPv6 addresses or host names for the RADIUS servers.
Obtain preshared keys from the RADIUS servers.
Ensure that the Nexus 5000 Series switch is configured as a RADIUS client of the AAA servers.
You can configure a maximum of 64 RADIUS servers on the Nexus 5000 Series switch.
"Configuring RADIUS Server Hosts" section on page
"Configuring Global Preshared Keys" section on page
"Allowing Users to Specify a RADIUS Server at Login" section on page 1-9
1-5.
1-6.
1-6.
Chapter 1
Configuring RADIUS
and the
OL-16597-01

Advertisement

Table of Contents
loading

Table of Contents