EasyManua.ls Logo

Cisco Aironet 1100 Series - Configuring Settings for All RADIUS Servers; Configuring the Access Point to Use Vendor-Specific RADIUS Attributes

Cisco Aironet 1100 Series
320 pages
To Next Page IconTo Next Page
To Next Page IconTo Next Page
To Previous Page IconTo Previous Page
To Previous Page IconTo Previous Page
Loading...
11-13
Cisco Aironet 1100 Series Access Point Installation and Configuration Guide
OL-2851-01
Chapter 11 Configuring RADIUS Servers
Configuring RADIUS
Configuring Settings for All RADIUS Servers
Beginning in privileged EXEC mode, follow these steps to configure global communication settings
between the access point and all RADIUS servers:
To return to the default setting for the retransmit, timeout, and deadtime, use the no forms of these
commands.
Configuring the Access Point to Use Vendor-Specific RADIUS Attributes
The Internet Engineering Task Force (IETF) draft standard specifies a method for communicating
vendor-specific information between the access point and the RADIUS server by using the
vendor-specific attribute (attribute 26). Vendor-specific attributes (VSAs) allow vendors to support their
own extended attributes not suitable for general use. The Cisco RADIUS implementation supports one
vendor-specific option by using the format recommended in the specification. Ciscos vendor-ID is 9,
and the supported option has vendor-type 1, which is named cisco-avpair. The value is a string with this
format:
protocol : attribute sep value *
Command Purpose
Step 1
configure terminal Enter global configuration mode.
Step 2
radius-server key string Specify the shared secret text string used between the access point and all
RADIUS servers.
Note The key is a text string that must match the encryption key used on
the RADIUS server. Leading spaces are ignored, but spaces within
and at the end of the key are used. If you use spaces in your key, do
not enclose the key in quotation marks unless the quotation marks
are part of the key.
Step 3
radius-server retransmit retries Specify the number of times the access point sends each RADIUS request
to the server before giving up. The default is 3; the range 1 to 1000.
Step 4
radius-server timeout seconds Specify the number of seconds an access point waits for a reply to a
RADIUS request before resending the request. The default is 5 seconds; the
range is 1 to 1000.
Step 5
radius-server deadtime minutes Specify the number of minutes the access point waits for a response from a
RADIUS server before skipping to the next server, thus avoiding the wait
for the request to timeout before trying the next configured server. The
default is 0; the range is 1 to 1440 minutes.
Note If you set up more than one RADIUS server, you must configure the
RADIUS server deadtime for optimal performance.
Step 6
radius-server attribute 32
include-in-access-req format %h
Configure the access point to send its system name in the NAS_ID attribute
for authentication.
Step 7
end Return to privileged EXEC mode.
Step 8
show running-config Verify your settings.
Step 9
copy running-config startup-config (Optional) Save your entries in the configuration file.

Table of Contents

Related product manuals