RADIUS security

TABLE 8 Brocade vendor-specific attributes for RADIUS (Continued)

Attribute name

Attribute ID

Data type

Description

 

 

 

 

foundry-802.1x-valid-lookup

7

integer

Specifies if 802.1x lookup is enabled:

 

 

 

0

- Disabled

 

 

 

1

- Enabled

 

 

 

 

foundry-MAC-based-VLAN-QOS

8

integer

Specifies the priority for MAC-based VLAN QOS:

 

 

 

0

- qos_priority_0

 

 

 

1

- qos_priority_1

 

 

 

2

- qos_priority_2

 

 

 

3

- qos_priority_3

 

 

 

4

- qos_priority_4

 

 

 

5

- qos_priority_5

 

 

 

6

- qos_priority_6

 

 

 

7

- qos_priority_7

 

 

 

 

 

Enabling SNMP to configure RADIUS

To enable SNMP access to RADIUS MIB objects on the device, enter a command such as the following.

Brocade(config)# enable snmp config-radius

Syntax: [no] enable snmp config-radius config-tacac>

The config-radiusparameter specifies the RADIUS configuration mode. RADIUS is disabled by default.

The config-tacacsparameter specifies the TACACS configuration mode. TACACS is disabled by default.

Identifying the RADIUS server to the Brocade device

To use a RADIUS server to authenticate access to a Brocade device, you must identify the server to the Brocade device.

Example

Brocade(config)# radius-server host 10.157.22.99

Syntax: radius-server host ip-addriipv6-addrserver-name[auth-port number] [acct-port number]

The host ip-addr ipv6-addr server-nameparameter is either an IP address or an ASCII text string.

The auth-portparameter is the Authentication port number. The default is 1645. The acct-portparameter is the Accounting port number. The default is 1646.

Brocade ICX 6650 Security Configuration Guide

47

53-1002601-01

 

Page 67
Image 67
Brocade Communications Systems 6650 Enabling Snmp to configure Radius, Identifying the Radius server to the Brocade device