Configuring Coa On The Switch - Cisco WS-CBS3032-DEL Software Configuration Manual

Software guide
Table of Contents

Advertisement

Chapter 6
Configuring Switch-Based Authentication

Configuring CoA on the Switch

Beginning in privileged EXEC mode, follow these steps to configure CoA on a switch. This procedure
is required.
Command
Step 1
configure terminal
Step 2
aaa new-model
Step 3
aaa server radius dynamic-author
Step 4
client {ip-address | name} [vrf vrfname]
[server-key string]
Step 5
server-key [0 | 7] string
Step 6
port port-number
Step 7
auth-type {any | all | session-key}
Step 8
ignore session-key
Step 9
ignore server-key
Step 10
authentication command bounce-port
ignore
Step 11
authentication command disable-port
ignore
Step 12
end
Step 13
show running-config
Step 14
copy running-config startup-config
To disable AAA, use the no aaa new-model global configuration command. To disable the AAA server
functionality on the switch, use the no aaa server radius dynamic authorization global configuration
command.
OL-13270-06
Purpose
Enter global configuration mode.
Enable AAA.
Configure the switch as an authentication, authorization, and accounting
(AAA) server to facilitate interaction with an external policy server.
Enter dynamic authorization local server configuration mode and specify
a RADIUS client from which a device will accept CoA and disconnect
requests.
Configure the RADIUS key to be shared between a device and RADIUS
clients.
Specify the port on which a device listens for RADIUS requests from
configured RADIUS clients.
Specify the type of authorization the switch uses for RADIUS clients.
The client must match all the configured attributes for authorization.
(Optional) Configure the switch to ignore the session-key.
For more information about the ignore command, see the
Intelligent Services Gateway Command Reference
(Optional) Configure the switch to ignore the server-key.
For more information about the ignore command, see the
Intelligent Services Gateway Command Reference
(Optional) Configure the switch to ignore a CoA request to temporarily
disable the port hosting a session. The purpose of temporarily disabling
the port is to trigger a DHCP renegotiation from the host when a VLAN
change occurs and there is no supplicant on the endpoint to detect the
change.
(Optional) Configure the switch to ignore a nonstandard command
requesting that the port hosting a session be administratively shut down.
Shutting down the port results in termination of the session.
Use standard CLI or SNMP commands to re-enable the port.
Return to privileged EXEC mode.
Verify your entries.
(Optional) Save your entries in the configuration file.
Cisco Catalyst Blade Switch 3130 and 3032 for Dell Software Configuration Guide
Controlling Switch Access with RADIUS
Cisco IOS
on Cisco.com.
Cisco IOS
on Cisco.com.
6-39

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

Catalyst blade 3130Catalyst blade 3032

Table of Contents