Configuring Radius - Extreme Networks ExtremeWare XOS Guide Manual

Concepts guide
Hide thumbs Also See for ExtremeWare XOS Guide:
Table of Contents

Advertisement

Authenticating Users Using RADIUS or TACACS+
Do not use the
keyword to set the shared secret. The
keyword is primarily for
encrypted
encrypted
the output of the
command, so the shared secret is not revealed in the command
show configuration
output.
Enabling and Disabling RADIUS Accounting
After you configure RADIUS accounting server information, you must enable accounting before the
switch begins transmitting the information. You must enable RADIUS authentication for accounting
information to be generated. You can enable and disable accounting without affecting the current state
of RADIUS authentication.
To enable RADIUS accounting, use the following command:
enable radius-accounting {mgmt-access | netlogin}
If you do not specify a keyword, RADIUS accounting is enabled on the switch for both management
and network login.
To disable RADIUS accounting, use the following command:
disable radius-accounting {mgmt-access | netlogin}
If you do not specify a keyword, RADIUS accounting is disabled on the switch for both management
and network login.
Per Command Authentication Using RADIUS
You can use the RADIUS implementation to perform per command authentication. Per command
authentication allows you to define several levels of user capabilities by controlling the permitted
command sets based on the RADIUS user name and password.
You do not need to configure any additional switch parameters to take advantage of this capability. The
RADIUS server implementation automatically negotiates the per command authentication capability
with the switch. For examples on per-command RADIUS configurations, see the next section.

Configuring RADIUS

You can define primary and secondary server communication information and, for each RADIUS server,
the RADIUS port number to use when talking to the RADIUS server. The default port value is 1812 for
authentication and 1813 for accounting. The client IP address is the IP address used by the RADIUS
server for communicating back to the switch.
NOTE
For information on how to use and configure your RADIUS server, please refer to the documentation that came with
your RADIUS server.
325
ExtremeWare XOS 11.3 Concepts Guide

Advertisement

Table of Contents
loading

This manual is also suitable for:

Extremeware xos 11.3

Table of Contents