Owner's Manual

Chapter 17. Security | 475
NETGEAR 8800 User Manual
Command authorization is not applicable because network login controls network access,
not management session access.
Except for the above differences, network login authentication is the same as described in
How NETGEAR Switches Work with RADIUS Servers on page 472.
Configuration Overview for Authenticating Network Login
Users
To configure the switch RADIUS client and the RADIUS server to authenticate network login
users, do the following:
1. Configure the switch RADIUS client for authentication as described in Configuring the
RADIUS Client for Authentication and Authorization on page 475.
2. If you want to use RADIUS accounting, configure the switch RADIUS accounting client as
described in
Configuring the RADIUS Client for Accounting on page 477.
3. Configure network login on the switch as described in Chapter 16, Network Login.
4. Configure the RADIUS server for authentication and NETGEAR VSAs as described in
Configuring User Authentication (Users File) on page 479.
5. If you want to use RADIUS accounting, configure a RADIUS accounting server as described
in the documentation for your RADIUS product.
Configuring the RADIUS Client
The following sections describe how to configure the XCM8800 RADIUS client component in
the XCM8800 software:
Configuring the RADIUS Client for Authentication and Authorization on page 475
Configuring the RADIUS Client for Accounting on page 477
For information on installing, configuring, and managing a RADIUS server, see the product
documentation for that server and the guidelines in
RADIUS Server Configuration Guidelines
on page 479.
Configuring the RADIUS Client for Authentication and
Authorization
The following sections provide information on configuring the RADIUS client for RADIUS
server authentication and authorization:
Specifying RADIUS Server Addresses on page 476
Configuring the RADIUS Client Timeout Value on page 476
Configuring the Shared Secret Password for RADIUS Communications on page 476
Enabling and Disabling the RADIUS Client Service on page 477