Technical data

ServerIron ADX Administration Guide 43
53-1002434-01
Configuring access control
1
Syntax: [no] radius-server host <ip-addr> | <server-name> [auth-port <number>] [acct-port
<number>]
Syntax: [no] radius-server [key <key-string>] [timeout <number>] [retransmit <number>]
[dead-time <number>]
The <ip-addr> | <server-name> parameter specifies either an IP address or an ASCII text string.
The optional <auth-port> parameter specifies Authentication port number. The default is 1645.
The optional <acct-port> parameter specifies the accounting port number. The default is 1646.
The <key-string> parameter specifies the encryption key.Valid key string length is from 1 – 16.
The timeout <number> parameter specifies how many seconds to wait before declaring a RADIUS
server timeout for the authentication request. The default timeout is 3 seconds. The range of
possible timeout values is from 1 – 15.
The retransmit <number> parameter specifies the maximum number of retransmission attempts.
When an authentication request timeout, the Brocade software will retransmit the request up to
the maximum number of retransmissions configured. The default retransmit value is 3 seconds.
The possible retransmit value is from 1 – 5.
When the software allows multiple authentication servers, the dead-time parameter specifies how
long the Brocade device waist for the primary authentication server to reply before deciding the
server is dead and trying to authenticate using the next server. The dead-time value can be from 1
– 5 seconds. The default is 3.
Password recovery
By default, the CLI does not require passwords. However, if someone has configured a password for
the ServerIron ADX but the password has been lost, you can regain super-user access to the
ServerIron ADX using the following procedure.
NOTE
Recovery from a lost password requires direct access to the serial port and a system reset.
Follow the steps listed below to recover from a lost password.
1. Start a CLI session over the serial interface to the ServerIron ADX.
2. Reboot the ServerIron ADX.
3. While the system is booting, before the initial system prompt appears, enter b to enter the boot
monitor mode.
4. Enter no password at the prompt. (You cannot abbreviate this command.)
5. Enter boot system flash primary at the prompt. This command causes the device to bypass the
system password check.
6. After the console prompt reappears, assign a new password.
Displaying information about the security feature
To display which security features are enabled on the system, enter the following command.