•
Configure the number of times Dell Networking OS retransmits RADIUS requests.
CONFIGURATION mode
radius-server retransmit
retries
•
retries
: the range is from 0 to 100. Default is
3 retries
.
•
Configure the time interval the system waits for a RADIUS server host response.
CONFIGURATION mode
radius-server timeout
seconds
•
seconds
: the range is from 0 to 1000. Default is
5 seconds
.
To view the configuration of RADIUS communication parameters, use the
show running-config
command in EXEC Privilege mode.
Monitoring RADIUS
To view information on RADIUS transactions, use the following command.
•
View RADIUS transactions to troubleshoot problems.
EXEC Privilege mode
debug radius
Microsoft Challenge-Handshake Authentication Protocol Support for
RADIUS Authentication
Dell Networking OS supports Microsoft Challenge-Handshake Authentication Protocol (MS-CHAPv2) with RADIUS authentication.
RADIUS is used to authenticate Telnet, SSH, console, REST, and OMI access to the switch based on the AAA configuration. By default, the
RADIUS client in the switch uses PAP (Password Authentication Protocol) for sending the login credentials to the RADIUS server. The
user-password attribute is added to the access-request message that is sent to the RADIUS server. Depending on the success or failure of
authentication, the RADIUS server sends back an access-accept or access-reject message respectively.
MS-CHAPv2 is secure than PAP. MS-CHAPv2 does not send user-password in the Access-Request message. It implements mutual
authentication based on the random challenges. MS-CHAP-Challenge and MS-CHAP2-Response attributes are sent in the Access-
Request message from the switch to the RADIUS Server. RADIUS Server validates the attributes and sends back MS-CHAPv2-Success
attribute in the Access-Accept message. If the validation fails, then RADIUS Server sends back the Access-Reject Message.
Enabling MS-CHAPv2 with the RADIUS authentication
Before enabling MS-CHAPv2 authentication on the switch, you must first Enable MS-CHAPv2 support in RADIUS Server.
To enable MS-CHAPv2 for the RADIUS authentication:
1
Enable RADIUS.
CONFIGURATION mode
aaa authentication login default radius local
2
Specify the protocol for authentication.
CONFIGURATION mode
aaa radius auth-method mschapv2
3
Establish a host address and password.
CONFIGURATION mode
radius-server host H key K
Security
711
Summary of Contents for S3048-ON
Page 1: ...Dell Configuration Guide for the S3048 ON System 9 11 2 5 ...
Page 137: ...0 Gi 1 1 Gi 1 2 rx Flow N A N A 0 0 No N A N A yes Access Control Lists ACLs 137 ...
Page 142: ...Figure 10 BFD Three Way Handshake State Changes 142 Bidirectional Forwarding Detection BFD ...
Page 241: ...Dell Control Plane Policing CoPP 241 ...
Page 287: ... RPM Synchronization GARP VLAN Registration Protocol GVRP 287 ...
Page 428: ...Figure 53 Inspecting the LAG Configuration 428 Link Aggregation Control Protocol LACP ...
Page 477: ...Figure 73 Configuring Interfaces for MSDP Multicast Source Discovery Protocol MSDP 477 ...
Page 478: ...Figure 74 Configuring OSPF and BGP for MSDP 478 Multicast Source Discovery Protocol MSDP ...
Page 483: ...Figure 77 MSDP Default Peer Scenario 2 Multicast Source Discovery Protocol MSDP 483 ...
Page 484: ...Figure 78 MSDP Default Peer Scenario 3 484 Multicast Source Discovery Protocol MSDP ...
Page 745: ...Figure 104 Single and Double Tag TPID Match Service Provider Bridging 745 ...
Page 746: ...Figure 105 Single and Double Tag First byte TPID Match 746 Service Provider Bridging ...