
30-24
Catalyst 4500 Series, Catalyst 2948G, Catalyst 2948G-GE-TX, and Catalyst 2980G Switches Software Configuration Guide—Release 8.2GLX
78-15908-01
Chapter 30 Configuring Switch Access Using AAA
Configuring Authentication
Enabling RADIUS Authentication
Note
Specify at least one RADIUS server before enabling RADIUS authentication on the switch. For
information on specifying a RADIUS server, see the
“Specifying RADIUS Servers” section on
page 30-23
.
You can enable RADIUS authentication for login and enable access to the switch. If desired, you can use
the console and telnet keywords to specify that RADIUS authentication is used only on console or Telnet
connections. If you are using both RADIUS and , you can use the primary keyword to force
the switch to try RADIUS authentication first.
To configure RADIUS authentication, perform this task in privileged mode:
Note
To use RADIUS authentication for enable mode, you need to create a user with the name $enab15$ on
the RADIUS server, and assign a password to that user. This user needs to be created in addition to your
assigned username and password on the RADIUS server (example: username john, password hello.)
After you log in to the Catalyst 4500 series switch with your assigned username and password
(john/hello), you can enter enable mode using the password that is assigned to the $enab15$ user.
If your RADIUS server does not support the $enab15$ username, you can set the service-type attribute
(attribute 6) to Administrative (value 6) for a RADUIS user to directly launch the user into enable mode
without asking for a separate enable password.
This example shows how to enable RADIUS authentication and verify the configuration:
Console> (enable) set authentication login radius enable
radius login authentication set to enable for console and telnet session.
Console> (enable) set authentication enable radius enable
radius enable authentication set to enable for console and telnet session.
Console> (enable) show authentication
Login Authentication: Console Session Telnet Session
--------------------- ---------------- ----------------
tacacs disabled disabled
radius enabled(primary) enabled(primary)
local enabled enabled
Task
Command
Step 1
Enable RADIUS authentication for normal login
mode.
set authentication login radius enable [all |
console | http | telnet] [primary]
Step 2
Enable RADIUS authentication for enable mode. set authentication enable radius enable [all |
console | http | telnet] [primary]
Step 3
Create a user $enab15$ on the RADIUS server,
and assign a password to that user.
See the Note on
Table 30-2 on page 30-24
for
additional information.
Step 4
Verify the RADIUS configuration.
show authentication