Administering the WMIC
Configuring and Enabling RADIUS
21
Cisco 3200 Series Wireless MIC Software Configuration Guide
Controlling WMIC Access with RADIUS
This section describes how to control administrator access to the WMIC using RADIUS.
RADIUS provides detailed accounting information and flexible administrative control over
authentication and authorization processes. RADIUS is facilitated through AAA and can be enabled only
through authentication, authorization, and accounting (AAA) commands. RADIUS and AAA are
disabled by default.
At a minimum, the host or hosts that run the RADIUS server software must be identified and the method
lists for RADIUS authentication must be defined. Optionally, method lists for RADIUS authorization
and accounting can be defined.
A method list defines the sequence and methods to be used to authenticate, to authorize, or to keep
accounts on a non-root bridge. Method lists are used to designate one or more security protocols to be
used, thus ensuring a backup system if the initial method fails. The software uses the first method listed
to authenticate, to authorize, or to keep accounts on non-root bridges; if that method does not respond,
the software selects the next method in the list. This process continues until there is successful
communication with a listed method or the method list is exhausted.
You must have access to and should configure a RADIUS server before you configure RADIUS features.
These sections describe RADIUS configuration:
•
Identifying the RADIUS Server Host
•
Configuring RADIUS Login Authentication
•
Defining AAA Server Groups
•
Configuring RADIUS Authorization for User Privileged Access and Network Services
•
Starting RADIUS Accounting
•
Configuring Settings for All RADIUS Servers
•
Configuring the Bridge to Use Vendor-Specific RADIUS Attributes
•
Configuring the Bridge for Vendor-Proprietary RADIUS Server Communication
•
Displaying the RADIUS Configuration
Note
For complete syntax and usage information for the commands used in this section, see the
Cisco IOS
Security Command Reference for Release 12.2
.
Identifying the RADIUS Server Host
Access point-to-RADIUS-server communication involves several components:
•
Hostname or IP address
•
Authentication destination port
•
Accounting destination port
•
Key string
•
Timeout period
•
Retransmission value