Configuring RADIUS
Enterasys G-Series CLI Reference 20-3
Filter-ID Attribute Formats
EnterasysNetworkssupportstwoFilter‐IDformats—“decorated”and“undecorated.”The
decoratedformathasthreeforms:
•Tospecifythepolicyprofiletoassigntotheauthenticatinguser(networkaccess
authentication):
Enterasys:version=1:policy=string
wherestringspecifiesthepolicyprofilename.Policyprofile namesarecase‐sensitive.
•Tospecifyamanagementlevel(managementaccess
authentication):
Enterasys:version=1:mgmt=level
wherelevelindicatesthemanagementlevel,eitherro,rw,orsu.
•Tospecifybothmanagementlevelandpolicyprofile:
Enterasys:version=1:mgmt=level:policy=string
Theundecoratedformatissimplyastringthatspecifiesapolicyprofilename.Theundecorated
formatcannotbeusedformanagementaccessauthentication.
DecoratedFilter‐IDsareprocessed
firstbytheswitch.IfnodecoratedFilter‐IDsarefound,then
undecoratedFilter‐IDsareprocessed.IfmultipleFilter‐IDsarefoundthatcontainconflicting
values,a Syslogmessageisgenerated.
Configuring RADIUS
Purpose
Toperformthefollowing:
•ReviewtheRADIUSclient/serverconfigurationontheswitch.
•EnableordisabletheRADIUSclient.
•Setlocalandremoteloginoptions.
•Setprimaryandsecondaryserverparameters,includingIPaddress,timeoutperiod,
authenticationrealm,andnumberofuserloginattemptsallowed.
•ResetRADIUSserversettingstodefaultvalues.
• ConfigureaRADIUS
accountingserver.
Commands
For information about... Refer to page...
show radius 20-4
set radius 20-5
clear radius 20-6
show radius accounting 20-7
set radius accounting 20-8
clear radius accounting 20-9