Specifications

Configuring RADIUS
SecureStack B2 Configuration Guide 19-3
EachusercanbeconfiguredintheRADIUSserverdatabasewithaRADIUSFilterIDattribute
thatspecifiesthenameofthepolicyprofileand/ormanagementleveltheusershouldbeassigned
uponsuccessfulauthentication.Duringtheauthenticati onprocess,whentheRADIUSserver
returnsaRADIUSAccessAcceptmessagethatincludes
aFilterIDmatchingapolicyprofilename
configuredontheswitch,theswitchthendynamicallyappliesthepolicyprofiletothephysical
porttheuser/deviceisauthenticatingon.
Filter-ID Attribute Formats
EnterasysNetworkssupportstwoFilterIDformats“decorated”and“undecorated.”The
decoratedformathasthreeforms:
•Tospecifythepolicyprofiletoassigntotheauthenticatinguser(networkaccess
authentication):
Enterasys:version=1:policy=string
wherestringspecifiesthe policyprofilename.Policyprofilenamesarecasesensitive.
•Tospecifyamanagementlevel(managementaccess
authentication):
Enterasys:version=1:mgmt=level
wherelevelindicatesthemanagementlevel,eitherro,rw,orsu.
•Tospecifybothmanagementlevelandpolicyprofile:
Enterasys:version=1:mgmt=level:policy=string
Theundecoratedformatissimplyastringthatspecifiesapolicyprofilename.Theundecorated
formatcannotbeusedformanagementaccessauthentication.
DecoratedFilterIDsareprocessed
firstbytheswitch.IfnodecoratedFilterIDsarefound,then
undecoratedFilterIDsare processed.IfmultipleFilterIDsarefoundthatcontainconflicting
values,aSyslogmessageisgenerated.
Configuring RADIUS
Purpose
Toperformthefollowing:
•ReviewtheRADIUSclient/serverconfigurationontheswitch.
•EnableordisabletheRADIUSclient.
•Setlocalandremoteloginoptions.
•Setprimaryandsecondaryserverparameters,includingIPaddress,timeoutperiod,
authenticationrealm,andnumberofuserloginattemptsallowed.
•ResetRADIUSserversettingstodefaultvalues.
ConfigureaRADIUS
accountingserver.