Table 4-4 – Avaya 580 User Manual

Page 139

background image

Document No. 10-300077, Issue 2

4-27

Security

Table 4-4. RADIUS Web Page Configuration Parameters

Parameter

Definition

Enable State

Enable or disable RADIUS on the switch.

Primary Server

IP Address - Enter the IP address for the primary

RADIUS server.

Shared Secret - Enter the shared secret the switch will use

for encrypting and decrypting passwords. Make sure the
primary server is configured with the exact same
characters (case sensitive). This value is itself encrypted
and will not be displayed anywhere (Web Agent or CLI)
once set. It can be changed by simply entering in a new
shared secret.

Secondary Server

IP Address - Enter IP address for the secondary RADIUS

server.

Shared Secret - Enter the shared secret the switch will use

for encrypting and decrypting passwords. Make sure the
secondary server is configured with the exact same
characters (case sensitive). This value is itself encrypted
and will not be displayed anywhere (Web Agent or CLI)
once set. It can be changed by simply entering in a new
shared secret.

Source IP
Address

Enter an IP interface address the switch will use as the
source IP address in the Access-Request messages. This
value must be an IP interface address on the switch. If set,
and the IP interface becomes disabled, RADIUS will not
function because the switch will not be able to send or
receive RADIUS messages.

If left 0.0.0.0 (the default), the switch automatically selects
a source IP address from one of its active interfaces. If you
use this setting, you must add each of the switch IP
addresses to the Client file on the RADIUS server since you
are not manually setting the source IP address.

Realm

Set this parameter only if realms are used on the RADIUS
server for organizing user accounts. If so, enter the realm
name for the user accounts that are authorized to log in to
the Avaya switch.

All user accounts that are authorized to log in to this switch
must be assigned to the same realm.

Group

Enter the group name.The group name will be included in
the Access-Request message sent to the RADIUS server.

If you specify a group name, all user accounts must be
assigned a group name on the RADIUS server and VSAs
must be set for the user accounts.

1 of 2

This manual is related to the following products: