CHAPTER 4: Configuration
43
4.3.5.A RADIUS Authentication Servers
If you want to, you can use the Remote Access Concentrator’s software implementation of a RADIUS
authentication client with a RADIUS authentication server acting as your device database. As a client,
the Concentrator sends access-request packets to designated RADIUS authentication servers to
authenticate remote devices.
If you are using RADIUS as your device database, you
must
configure information for a Primary RADIUS
Authentication Server. Configuring a Secondary Server is optional; in the event that the primary server does
not respond to system requests, the secondary server will be queried for device authentication information.
To enter information for RADIUS authentication servers, take these steps:
1. Select Authentication Servers from the RADIUS menu. This menu will appear:
2. Use the space bar to toggle the Primary Server’s Status to ENABLED.
3. Enter the IP Address of the primary server.
4. Enter the Shared Secret between the Concentrator and the primary server.
5. Enter the UDP Port Number used by the server. The UDP port number defaults to 1812 because this is
the port number assigned for RADIUS authentication in RFC 2138. However, many RADIUS servers use
UDP port number 1645 for authentication instead.
6.
If you’re using a secondary RADIUS authentication server:
Repeat steps 2 through 5 for the Secondary Server.
(In most cases, the address of the secondary server will not be the same as that of the primary server. If,
however, you have two RADIUS servers running on the same PC but using different UDP ports, the two
servers
would
have the same IP address.)