beautypg.com

Radius configuration, Switch configuration tasks – Allied Telesis AlliedWare Plus Operating System Version 5.4.4C (x310-26FT,x310-26FP,x310-50FT,x310-50FP) User Manual

Page 1259

background image

RADIUS Introduction and Configuration

Software Reference for x310 Series Switches

C613-50046-01 REV A

AlliedWare Plus

TM

Operating System - Version 5.4.4C

46.9

RADIUS Configuration

This section describes how to configure RADIUS with the available AAA commands. For a
description of AAA commands, refer to the

AAA Commands

chapter. For a description of

the RADIUS commands used, refer to the

RADIUS Commands

chapter.

RADIUS is often used in a variety of networks that need high security while maintaining
access for remote users. RADIUS is suitable for the following networks that require access
security:

Networks with multiple-vendor access servers, each supporting RADIUS. For example,
access servers from several vendors use a single RADIUS server-based security
database.

Networks in which a user may access a single service. Using RADIUS, you can control
user access to a single host, or to a single utility such as Telnet.

Networks that require accounting. You can use RADIUS accounting independent of
RADIUS authentication. The RADIUS accounting functions allow data to be sent at the
start and end of services, indicating the amount of resources (time, packets, bytes)
used.

Switch Configuration Tasks

To configure RADIUS on your switch or access server, you must perform the following
tasks:

Use the aaa authentication command to define method lists for RADIUS
authentication. For information about this command, refer to the

AAA Commands

chapter.

Use authentication commands to enable the defined method lists to be used. For
more information, refer to the

Authentication Commands

chapter.

The following configuration tasks are optional:

You can use the

aaa group server

command to group selected RADIUS hosts for

specific services. For detailed information about this command, refer to the

AAA

Server Groups Configuration

section in this chapter and refer to the

AAA

Commands

chapter.

You can use the

aaa accounting login

command to enable accounting for RADIUS

connections. For information about this command, refer to the

AAA Commands

chapter.

This section describes how to set up RADIUS for authentication and accounting on your
network, and includes the following sections:

Switch to RADIUS Server Communication (Required)

Configuring AAA Server Groups (Optional)

Configuring AAA Server Groups with Deadtime (Optional)

Specifying RADIUS Authentication

Specifying RADIUS Accounting (Optional)

For RADIUS configuration examples using the commands in this chapter, refer to the
section

RADIUS Configuration Examples

at the end of this chapter.