User's Manual
13-8
Cisco IOS Software Configuration Guide for Cisco Aironet Access Points
OL-11350-01
Chapter 13 Configuring RADIUS and TACACS+ Servers
 Configuring and Enabling RADIUS
authenticate users; if that method fails to respond, the software selects the next authentication method 
in the method list. This process continues until there is successful communication with a listed 
authentication method or until all defined methods are exhausted. If authentication fails at any point in 
this cycle—meaning that the security server or local username database responds by denying the user 
access—the authentication process stops, and no other authentication methods are attempted.
Beginning in privileged EXEC mode, follow these steps to configure login authentication. This 
procedure is required.
Command Purpose
Step 1
configure terminal Enter global configuration mode.
Step 2
aaa new-model Enable AAA.
Step 3
aaa authentication login {default | 
list-name} method1 [method2...]
Create a login authentication method list.
• To create a default list that is used when a named list is not specified 
in the login authentication command, use the default keyword 
followed by the methods that are to be used in default situations. The 
default method list is automatically applied to all interfaces. For more 
information on list names, click this link: 
http://www.cisco.com/univercd/cc/td/doc/product/software/ios122/1
22cgcr/fsecur_c/fsaaa/scfathen.htm#xtocid2
• For method1..., specify the actual method the authentication 
algorithm tries. The additional methods of authentication are used 
only if the previous method returns an error, not if it fails.
Select one of these methods:
• line—Use the line password for authentication. You must define a 
line password before you can use this authentication method. Use the 
password password line configuration command.
• local—Use the local username database for authentication. You must 
enter username information in the database. Use the username 
password global configuration command.
• radius—Use RADIUS authentication. You must configure the 
RADIUS server before you can use this authentication method. For 
more information, see the “Identifying the RADIUS Server Host” 
section on page 13-5.
Step 4
line [console | tty | vty] line-number 
[ending-line-number]
Enter line configuration mode, and configure the lines to which you want 
to apply the authentication list.
Step 5
login authentication {default | 
list-name}
Apply the authentication list to a line or set of lines.
• If you specify default, use the default list created with the aaa 
authentication login command.
• For list-name, specify the list created with the aaa authentication 
login command.
Step 6
radius-server attribute 32 
include-in-access-req format %h
Configure the access point to send its system name in the NAS_ID 
attribute for authentication.
Step 7
end Return to privileged EXEC mode.
Step 8
show running-config Verify your entries.
Step 9
copy running-config startup-config (Optional) Save your entries in the configuration file.










