Aruba IAP-335 User Manual page 157

Instant software
Hide thumbs Also See for IAP-335:
Table of Contents

Advertisement

Table 33: RADIUS Server Configuration Parameters
Parameter
Auth port
Accounting
port
Shared key
Retype key
Timeout
Retry count
RFC 3576
NAS IP
address
NAS
Identifier
Dead Time
Dynamic
RADIUS
proxy
parameters
Aruba Instant 6.5.0.0-4.3.0.0 | User Guide
Description
NAS identifier
l
For more information on RadSec configuration, see
page
161.
Enter the authorization port number of the external RADIUS server within the range of 1–65,535.
The default port number is 1812.
Enter the accounting port number within the range of 1–65,535. This port is used for sending
accounting records to the RADIUS server. The default port number is 1813.
Enter a shared key for communicating with the external RADIUS server.
Re-enter the shared key.
Specify a timeout value in seconds. The value determines the timeout for one RADIUS request. The
IAP retries to send the request several times (as configured in the Retry count) before the user
gets disconnected. For example, if the Timeout is 5 seconds, Retry counter is 3, user is
disconnected after 20 seconds. The default value is 5 seconds.
Specify a number between 1 and 5. Indicates the maximum number of authentication requests that
are sent to the server group, and the default value is 3 requests.
Select Enabled to allow the IAPs to process RFC 3576-compliant Change of Authorization (CoA) and
disconnect messages from the RADIUS server. Disconnect messages cause a user session to be
terminated immediately, whereas the CoA messages modify session authorization attributes such
as data filters.
Allows you to configure an arbitrary IP address to be used as RADIUS attribute 4, NAS IP Address,
without changing source IP Address in the IP header of the RADIUS packet.
NOTE: If you do not enter the IP address, the VC IP address is used by default when Dynamic
RADIUS Proxy is enabled.
Allows you to configure strings for RADIUS attribute 32, NAS Identifier, to be sent with RADIUS
requests to the RADIUS server.
Specify a dead time for authentication server in minutes.
When two or more authentication servers are configured on the IAP and a server is unavailable, the
dead time configuration determines the duration for which the authentication server would be
available if the server is marked as unavailable.
Specify the following dynamic RADIUS proxy (DRP) parameters:
DRP IP—IP address to be used as source IP for RADIUS packets.
l
DRP Mask—Subnet mask of the DRP IP address.
l
DRP VLAN—VLAN in which the RADIUS packets are sent.
l
DRP Gateway—Gateway IP address of the DRP VLAN.
l
For more information on dynamic RADIUS proxy parameters and configuration procedure, see
Configuring Dynamic RADIUS Proxy Parameters on page
Enabling RADIUS Communication over TLS on
162.
Authentication and User Management |
157

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents