Technical data

BLADE OS 5.1 Application Guide
BMD00136, November 2009 Chapter 1: Accessing the Switch
29
RADIUS Authentication Features in Blade OS
Blade OS supports the following RADIUS authentication features:
Supports RADIUS client on the switch, based on the protocol definitions in RFC 2138 and
RFC 2866.
Allows RADIUS secret password up to 32 bytes and less than 16 octets.
Supports secondary authentication server so that when the primary authentication server is
unreachable, the switch can send client authentication requests to the secondary authentication
server. Use the following command to show the currently active RADIUS authentication
server:
Supports user-configurable RADIUS server retry and time-out values:
Time-out value = 1-10 seconds
Retries = 1-3
The switch will time out if it does not receive a response from the RADIUS server in 1-3
retries. The switch will also automatically retry connecting to the RADIUS server before it
declares the server down.
Supports user-configurable RADIUS application port.
The default is 1812/UDP-based on RFC 2138. Port 1645 is also supported.
Allows network administrator to define privileges for one or more specific users to access the
switch at the RADIUS user database.
Switch User Accounts
The user accounts listed in Table 2 can be defined in the RADIUS server dictionary file.
RS G8000 (config)# show radius-server
Table 2 User Access Levels
User Account Description and Tasks Performed Password
User The User has no direct responsibility for switch management.
He/she can view all switch status information and statistics
but cannot make any configuration changes to the switch.
user