Generic 802.1x COMMANDS
Page 164
7950 SR OS System Management Guide
server (dot1x)
Syntax
server server-index address ip-address secret key
[
hash
|
hash2
] [
auth-port
auth-port
]
[
acct-port
acct-port
] [
type
server-type
]
no server index
Context
config>system>security> dot1x>radius-plcy
Description
This command adds a Dot1x server and configures the Dot1x server IP address, index, and key val-
ues.
Up to five Dot1x servers can be configured at any one time. Dot1x servers are accessed in order from
lowest to highest index for authentication requests until a response from a server is received. A higher
indexed server is only queried if no response is received from a lower indexed server (which implies
that the server is not available). If a response from a server is received, no other Dot1x servers are
queried. It is assumed that there are multiple identical servers configured as backups and that the
servers do not have redundant data.
The
no
form of the command removes the server from the configuration.
Default
No Dot1x servers are configured.
Parameters
server-index —
The index for the Dot1x server. The index determines the sequence in which the
servers are queried for authentication requests. Servers are queried in order from lowest to
highest index.
Values
1
—
5
address ip-address —
The IP address of the Dot1x server. Two Dot1x servers cannot have the same
IP address. An error message is generated if the server address is a duplicate.
secret key —
The secret key to access the Dot1x server. This secret key must match the password on
the Dot1x server.
Values
Up to 128 characters in length.
hash —
Specifies the key is entered in an encrypted form. If the
hash
parameter is not used, the key
is assumed to be in a non-encrypted, clear text form. For security, all keys are stored in encrypted
form in the configuration file with the
hash
parameter specified.
hash2 —
Specifies the key is entered in a more complex encrypted form. If the
hash2
parameter is
not used, the less encrypted
hash
form is assumed.
acct-port acct-port —
The UDP port number on which to contact the RADIUS server for accounting
requests.
auth-port auth-port —
specifies a UDP port number to be used as a match criteria.
Values
1 — 65535
type server-type —
Specifies the server type.
Values
authorization, accounting, combined
Summary of Contents for 7950 SR
Page 10: ...Page 10 7950 SR OS System Management Guide List of Figures...
Page 14: ...About This Guide Page 14 7950 SR OS System Management Guide...
Page 16: ...Alcatel Lucent 7950 SR Router Configuration Process Page 16 7950 SR OS System Management Guide...
Page 56: ...Configuration Notes Page 56 7950 SR OS System Management Guide...
Page 88: ...Configuring Login Controls Page 88 7950 SR OS System Management Guide...
Page 106: ...Security Command Reference Page 106 7950 SR OS System Management Guide...
Page 206: ...Distributed CPU Protection Commands Page 206 7950 SR OS System Management Guide...
Page 244: ...Debug Commands Page 244 7950 SR OS System Management Guide...
Page 254: ...Configuration Notes Page 254 7950 SR OS System Management Guide...
Page 276: ...SNMP Security Commands Page 276 7950 SR OS System Management Guide...
Page 296: ...Show Commands Page 296 7950 SR OS System Management Guide...
Page 322: ...Configuration Notes Page 322 7950 SR OS System Management Guide...
Page 358: ...Log Management Tasks Page 358 7950 SR OS System Management Guide...
Page 454: ...Facility Alarm List Page 454 7950 SR OS System Management Guide...
Page 460: ...Standards and Protocols Page 460 Standards and Protocols...