RADIUS Authentication, Authorization, and Accounting

 

Configuring the Switch for RADIUS Authentication

 

 

Note

If you want to configure RADIUS accounting on the switch, go to page 5-37:

 

“Configuring RADIUS Accounting” instead of continuing here.

 

Syntax: [no] radius-server host < ip-address> [oobm]

 

 

Adds a server to the RADIUS configuration or (with no)

 

deletes a server from the configuration. You can configure

 

up to three RADIUS server addresses. The switch uses the

 

first server it successfully accesses. (Refer to “Changing

 

the RADIUS Server Access Order” on page 5-50.)

 

For switches that have a separate out-of-band manage-

 

ment port, the oobm parameter specifies that the RADIUS

 

traffic will go through the out-of-band management

 

(OOBM) port.

 

[auth-port < port-number>]

 

Optional. Changes the UDP destination port for authenti-

 

cation requests to the specified RADIUS server (host). If

 

you do not use this option with the radius-server host

 

command, the switch automatically assigns the default

 

authentication port number. The auth-portnumber must

 

match its server counterpart. (Default: 1812)

 

[acct-port < port-number>]

 

Optional. Changes the UDP destination port for account-

 

ing requests to the specified RADIUS server. If you do not

 

use this option with the radius-server host command, the

 

switch automatically assigns the default accounting port

 

number. The acct-portnumber must match its server coun-

 

terpart.(Default: 1813)

5-15