Specifications
Security Options 73
Chapter 5
To configure general authentication server settings, navigate to
Configuration >
Security > AAA Servers > General
, as shown in the figure below.
FIGURE 5-9 AAA General Parameters
Configuration parameters for this section are:
User Idle Timeout – Determines the maximum amount of time a user may
remain idle before being deauthenticated and removed from the system. The
default is 5 minutes.
Authentication Server Dead Time – Determines the maximum amount of time
an authentication server may remain unresponsive before it is considered
down. Multiple authentication servers may be configured for each
authentication method – if the first server in the list is down, the request will
be sent to the second server.
The equivalent CLI configuration for the example above is:
aaa timers idle-timeout 5
aaa timers dead-time 10
RADIUS
RADIUS is the most commonly used type of authentication server. RADIUS is
flexible, extensible, and has a high degree of interoperability. To configure
RADIUS server settings navigate to
Configuration > Security > AAA Servers >
RADIUS
, as shown in the figure below.