7-25
Catalyst 2950 Desktop Switch Software Configuration Guide
78-14982-01
Chapter 7 Adminis tering the Switch Controlling Switch Access with RADIUS
To disable AAA, use the no aaa new-model global co nfigur ation c omm and. To disa ble AA A
authentication, use the no aaa auth enti ca tion log in {default | list-name} method1 [method2...] global
configuration command. To either disable RADIUS authentication for logins or to return to the default
value, use th e no login authe ntication {default | list-name} l ine configurati on comma nd.

Defining AAA Server Groups

You can configure the switch to use AAA server groups to group existing server hosts for authentication.
You select a subset of the configured server hosts and use them for a particular service. The server group
is used with a global server-host list, which lists the IP addresses of the selected server hosts.
Server g roups also can include multiple host entries for the same server if each entry has a unique
identi fier (the combinat ion of the IP addr ess and UDP por t number), all owing different ports to be
individually defined as RADIUS hosts providing a specific AAA service. If you configure two different
host ent ries on the sam e RADIU S server for the sam e servic e, (for examp le, accou nting) , the seco nd
configured host entry acts as a fail-over backup to the first one.
You use the server group se rver configurat ion c om mand to a sso cia te a part icu lar se rver w ith a d efined
group server. You can either identify the server by its IP addre ss or identify multiple host instances or
entries by using the optional auth-port and acct-port keywords.