RADIUS Authentication and Accounting

General RADIUS Setup Procedure

General RADIUS Setup ProcedurePreparation:

1.Configure one to three RADIUS servers to support the switch. (That is, one primary server and one or two backups.) Refer to the documentation provided with the RADIUS server application.

2.Before configuring the switch, collect the information outlined below.

Table 5-1. Preparation for Configuring RADIUS on the Switch

Determine the access methods (console, Telnet, Port-Access (802.1X), SSH, and/or web browser interface) for which you want RADIUS as the primary authentication method. Consider both Operator (login) and Manager (enable) levels, as well as which secondary authentication methods to use (local or none) if the RADIUS authentication fails or does not respond.

ProCurve> show authentication

Status and Counters - Authentication Information

Login Attempts : 3

 

 

 

 

Respect Privilege : Disabled

 

 

Console access

 

 

 

 

 

 

requires Local as

 

Login

Login

Enable

Enable

secondary method to

 

prevent lockout if the

Access Task

Primary

Secondary

Primary

Secondary

primary RADIUS

-----------

+

----------

----------

----------

---------

- access fails due to loss

Console

Radius

Local

Radius

Local

of RADIUS server

Telnet

Radius

None

Radius

None

access or other

Port-Access

EapRadius

 

 

 

problems with the

 

 

 

server.

Webui

Radius

None

Radius

None

 

SSH

Radius

None

Radius

None

 

Web-Auth

ChapRadius

 

 

 

 

MAC-Auth

ChapRadius

 

 

 

 

Figure 5-1. Example of Possible RADIUS Access Assignments

Determine the IP address(es) of the RADIUS server(s) you want to support the switch. (You can configure the switch for up to three RADIUS servers.)

If you need to replace the default UDP destination port (1812) the switch uses for authentication requests to a specific RADIUS server, select it before beginning the configuration process.

If you need to replace the default UDP destination port (1813) the switch uses for accounting requests to a specific Radius server, select it before beginning the configuration process.

5-5