Verifying Radius Configuration Using Fabric Manager; Verifying Radius Configuration Using The Cli - Cisco 9134 - MDS Multilayer Fabric Switch Troubleshooting Manual

Mds 9000 family
Hide thumbs Also See for 9134 - MDS Multilayer Fabric Switch:
Table of Contents

Advertisement

AAA Issues
S e n d d o c u m e n t a t i o n c o m m e n t s t o m d s f e e d b a c k - d o c @ c i s c o . c o m

Verifying RADIUS Configuration Using Fabric Manager

To verify or change the RADIUS configuration using Fabric Manager, follow these steps:
Step 1
Choose Switches > Security > AAA > RADIUS and select the Servers tab. You see the RADIUS
configuration in the Information pane.
Step 2
Highlight the server that you need to change and click Delete Row to delete this server configuration.
Step 3
Click Create Row to add a new RADIUS server.
Set the KeyType and Key fields to the preshared key configured on the RADIUS server.
Step 4
Set the AuthPort and AcctPort fields to the authentication and accounting ports configured on the
Step 5
RADIUS server.
Set the TimeOut value and click Apply to save these changes.
Step 6
Select the CFS tab and select commit from the Config Action drop-down menu and click Apply
Step 7
Changes to distribute these changes to all switches in the fabric.

Verifying RADIUS Configuration Using the CLI

To verify or change the RADIUS configuration using the CLI, follow these steps:
Use the show radius-server command to display configured RADIUS parameters.
Step 1
switch# show radius-server
Global RADIUS shared secret:*******
retransmission count:5
timeout value:10
following RADIUS servers are configured:
Step 2
Use the radius-server host ip-address key command to set the preshared key to match what is
configured on your RADIUS server.
Use the radius-server host ip-address auth-port command to set the authentication port to match what
Step 3
is configured on your RADIUS server.
Use the radius-server host ip-address acc-port command to set the accounting port to match what is
Step 4
configured on your RADIUS server.
Use the radius-server timeout command to set the period in seconds for the switch to wait for a
Step 5
response from all RADIUS servers before the switch declares a timeout failure.
Use the radius commit command to commit any changes and distribute to all switches in the fabric.
Step 6
Cisco MDS 9000 Family Troubleshooting Guide, Release 3.x
17-4
myradius.cisco.users.com:
available for authentication on port:1812
available for accounting on port:1813
10.1.1.1:
available for authentication on port:1812
available for accounting on port:1813
RADIUS shared secret:******
10.2.2.3:
available for authentication on port:1812
available for accounting on port:1813
RADIUS shared secret:******
Chapter 17
Troubleshooting RADIUS and TACACS+
OL-9285-05

Hide quick links:

Advertisement

Table of Contents

Troubleshooting

loading

Table of Contents