Installation manual

3-59
SIGNAMAX LLC • www.signamax.eu
Command Attributes
Authentication – Select the authentication, or authentication sequence required:
- Local – User authentication is performed only locally by the switch.
- RADIUS – User authentication is performed using a RADIUS server only.
- TACACS – User authentication is performed using a TACACS+ server only.
- [authentication sequence] – User authentication is performed by up to three
authentication methods in the indicated sequence.
RADIUS Settings
- Global Provides globally applicable RADIUS settings.
- Server Index – Specifies one of five RADIUS servers that may be configured. The
switch attempts authentication using the listed sequence of servers. The process
ends when a server either approves or denies access to a user.
- Server IP Address
5
– Address of the RADIUS server.
- Authentication Port Number – Network (UDP) port of authentication server used for
authentication messages. (Range: 1-65535; Default: 1812)
- Accounting Port Number – UDP port on authentication server used for accounting
messages. (Range: 1-65535; Default: 1813)
- Number of Server Transmits – Number of times the switch tries to authenticate
logon access via the authentication server. (Range: 1-30; Default: 2)
- Timeout for a reply – The number of seconds the switch waits for a reply from the
RADIUS server before it resends the request. (Range: 1-65535; Default: 5)
RADIUS Attributes
NAS IP Address – Specifies the IP address of the Network Access Server (NAS) to
use in the attribute 4 address field in packets sent to the RADIUS server. (Default: The
IP address of the interface that connects the switch to the RADIUS server.)
The IP address of the interface connecting the switch (i.e., the NAS) to the RADIUS
server is used in the IP headers of RADIUS packets sent to the server. This address
is also used by default in the attribute 4 field inside of RADIUS packets sent to the
server.
It may be necessary for certain AAA processes to configure the attribute 4 field to an
address other than that of the switch’s connecting interface. However, setting this field
to an address other than that of the actual interface connecting the switch to the
RADIUS server will not affect the IP address used inside the IP headers of RADIUS
packets sent from the switch.
Some AAA clients may try to change the attribute 4 address. Setting the NAS IP
address in the attribute 4 field prevents these clients from changing this address.
5. A Server Index must be selected to display this item.