Access Security Guide K/KA/KB.15.15

Configuring the switch for RADIUS authentication
Configure RADIUS authentication for controlling access through one or more of the following
Serial port
Telnet
SSH
Port-Access (802.1X)
WebAgent
1. RADIUS authentication on the switch must be enabled to override the default authentication
operation which is to automatically assign an authenticated client to the operator privilege
level. This applies the privilege level specified by the service type value received from the
RADIUS server, see “Configuring authentication for access methods RADIUS is to protect”
(page 144).
2. Configure the switch for accessing one or more RADIUS servers (one primary server and up
to two backup servers):
Server IP address
(Optional) UDP destination port for authentication requests (default: 1812; recommended)
(Optional) UDP destination port for accounting requests (default: 1813; recommended)
(Optional) Encryption key for use during authentication sessions with a RADIUS server.
This key overrides the global encryption key you can also configure on the switch, and
must match the encryption key used on the specified RADIUS server. Default: null.
NOTE: Step 2 assumes you have already configured the RADIUS servers to support the
switch. See your RADIUS server documentation for details.
Configuring 143