Chapter 29: Security
STANDARD Revision 1.0
C4® CMTS Release 8.3 User Guide
© 2016 ARRIS Enterprises LLC. All Rights Reserved.
838
The C4/c CMTS supports 16 independently configurable RADIUS server groups. Configuration information must include
the group name and a list of RADIUS servers belonging to the group.
Server and server group configuration information persists across system reboots and power-cycles.
By default no RADIUS servers or server groups exist; the skeleton database does not contain RADIUS server
configuration information.
RADIUS Authentication Method Lists
The authentication function may be assigned to one or more RADIUS server groups, or to any of several local methods
including the line password, the enable password, or the local user/password file. Moreover, authentication may be
assigned to several of these methods in order of preference such that method n+1 is employed if method n is not
available. This ordered list of methods is referred to as an authentication method list. The authentication method lists have
the following characteristics:
The C4/c CMTS supports 32 independently configurable authentication method lists.
Configuration information must include the list’s name and an ordered list of authentication methods (RADIUS,
, local password file, line password, password, and none).
There is a default authentication method list named default that includes the local and none methods in that order. All
lines are configured to use the default authentication list.
Authentication method list configuration information persists across system reboots and power-cycles.
For authentication method, choose from the following types: none, line, local, tacacs <group>, radius <group>.
Once an authentication method list is defined, the user can apply it to a console or vty line for only login authentication,
only enable authentication, or both login and enable authentication.
Sample Configuration for RADIUS Authentication
Each server is configured with an IP address, shared secret, authentication port number, timeout value, and retransmission
limit. Each group is configured with a group name and one or more RADIUS servers. All servers are automatically assigned
to the RADIUS server group named default.
Use the following command to configure RADIUS servers and server groups.
configure radius [no] { group string host ipAddress | host ipAddress key string [hidden] [auth-port
integer] [timeout integer] [retransmit integer] }
Configure the source interface that the C4/c CMTS will use for all RADIUS packets that are sent to the RADIUS server: