Installation guide
Switch Security
6-76
6.9.3.2 Radius Proxy Server Configuration
The switch can send Radius requests to a properly configured proxy Radius server. A user's access request is
sent to a proxy server if it cannot be authenticated by a local server. The switch forwards the access request
to a proxy server that can authenticate the user based on the realm. The proxy server checks the information
in the user access request and either accepts or rejects the request. If the proxy target server accepts the
request, it returns configuration information specifying the type of connection service required to authenticate
the user.
To configure Radius proxy server support:
1. Select Security > Radius Server from the main menu.
2. Ensure the Configuration tab is selected.
3. Select the Proxy Servers tab from the bottom of the Configuration tab.
The Proxy Servers tab displays the user ID suffix (index), IP address and port number of the switch’s
existing proxy server configurations.
4. To remove an existing Radius proxy server configuration from the table of configurations available to
the switch, select the configuration and click the Delete button.
5. To create a new Radius proxy server configuration, click the Add button at the bottom of the screen.
a. Create a new User ID Suffix serving as an abbreviation for the configuration to differentiate it
from other configurations with similar attributes.
b. Specify the IP Address of the new Radius proxy server.
c. Enter the TCP/IP port number for the port used by the proxy Radius server.
d. Specify a Radius Shared Secret for authenticating the Radius client.
The shared secret is used to verify Radius messages. It is a case-sensitive string that can include
letters, numbers, or symbols. Make the shared secret at least 31 characters long to protect the
Radius server from brute-force attacks.
e. Refer to the Status field for the current state of the requests made from applet. This field
displays error messages if something goes wrong in the transaction between the applet and the
switch.
f. Click OK to use the changes to the running configuration and close the dialog.
g. Click Cancel to close the dialog without committing updates to the running configuration