Configuring RADIUS
SecureStack B3 Configuration Guide 20-3
configuredontheswitch,theswitchthendynamicallyappliesthepolicyprofiletothephysical
porttheuser/deviceisauthenticatingon.
Filter-ID Attribute Formats
EnterasysNetworkssupportstwoFilter‐IDformats—“decorated”and“undecorated.”The
decoratedformathasthreeforms:
•Tospecifythepolicyprofiletoassigntotheauthenticatinguser(networkaccess
authentication):
Enterasys:version=1:policy=string
wherestringspecifiesthepolicyprofilename.Policyprofilenamesarecase‐sensitive.
•Tospecifyamanagementlevel(managementaccess
authentication):
Enterasys:version=1:mgmt=level
wherelevelindicatesthemanagementlevel,eitherro,rw,orsu.
•Tospecifybothmanagementlevelandpolicyprofile:
Enterasys:version=1:mgmt=level:policy=string
Theundecoratedformatissimplyastringthatspecifiesapolicyprofilename.Theundecorated
formatcannotbeusedformanagementaccessauthentication.
DecoratedFilter‐IDsareprocessed
firstbytheswitch.IfnodecoratedFilter‐IDsarefound,then
undecoratedFilter‐IDsareprocessed.IfmultipleFilter‐IDsarefoundthatcontainconflicting
values,aSyslogmessageisgenerated.
Configuring RADIUS
Purpose
Toperformthefollowing:
•ReviewtheRADIUSclient/serverconfigurationontheswitch.
•EnableordisabletheRADIUSclient.
•Setlocalandremoteloginoptions.
•Setprimaryandsecondaryserverparameters,includingIPaddress,timeoutperiod,
authenticationrealm,andnumberofuserloginattemptsallowed.
•ResetRADIUSserversettingstodefaultvalues.
• ConfigureaRADIUS
accountingserver.
Commands
For information about... Refer to page...
show radius 20-4
set radius 20-5
clear radius 20-7
show radius accounting 20-7