Authenticating Users
Summit 300-48 Switch Software User Guide
43
Authenticating Users
ExtremeWare provides a Radius client to authenticate switch admin users who login to the switch:
RADIUS Client
Remote Authentication Dial In User Service (RADIUS, RFC 2138) is a mechanism for authenticating and
centrally administrating access to network nodes. The ExtremeWare RADIUS client implementation
allows authentication for Telnet or console access to the switch.
You can define a primary and secondary RADIUS server for the switch to contact. When a user
attempts to login using Telnet, http, or the console, the request is relayed to the primary RADIUS server,
and then to the secondary RADIUS server, if the primary does not respond. If the RADIUS client is
enabled, but access to the RADIUS primary an secondary server fails, the switch uses its local database
for authentication.
The privileges assigned to the user (admin versus nonadmin) at the RADIUS server take precedence
over the configuration in the local switch database.
Configuring RADIUS Client
You can define primary and secondary server communication information, and for each RADIUS server,
the RADIUS port number to use when talking to the RADIUS server. The default port value is 1645. The
client IP address is the IP address used by the RADIUS server for communicating back to the switch.
RADIUS commands are described in Table 11.
Table 11: RADIUS Commands
Command
Description
config radius [primary | secondary] server
[<ipaddress> | <hostname>] {<udp_port>} client-ip
<ipaddress>
Configures the primary and secondary
RADIUS server. Specify the following:
•
[primary | secondary]
—
Configure either the primary or
secondary RADIUS server.
•
[<ipaddress> | <hostname>]
—
The IP address or hostname of the
server being configured.
•
<udp_port>
— The UDP port to use
to contact the RADUIS server. The
default UDP port setting is 1645.
•
client-ip <ipaddress>
— The IP
address used by the switch to identify
itself when communicating with the
RADIUS server.
The RADIUS server defined by this
command is used for user name
authentication and CLI command
authentication.
config radius [primary | secondary] shared-secret
{encrypted} <string>
Configures the authentication string used
to communicate with the RADIUS server.
Summary of Contents for Summit 300-48
Page 12: ...12 Summit 300 48 Switch Software User Guide Figures...
Page 22: ...22 Summit 300 48 Switch Software User Guide ExtremeWare Overview...
Page 34: ...34 Summit 300 48 Switch Software User Guide Accessing the Switch...
Page 62: ...62 Summit 300 48 Switch Software User Guide Configuring Ports on a Switch...
Page 72: ...72 Summit 300 48 Switch Software User Guide Virtual LANs VLANs...
Page 82: ...82 Summit 300 48 Switch Software User Guide Wireless Networking...
Page 94: ...94 Summit 300 48 Switch Software User Guide Unified Access Security...
Page 102: ...102 Summit 300 48 Switch Software User Guide Power Over Ethernet...
Page 120: ...120 Summit 300 48 Switch Software User Guide Access Policies...
Page 168: ...168 Summit 300 48 Switch Software User Guide IP Unicast Routing...
Page 172: ...172 Summit 300 48 Switch Software User Guide Safety Information...
Page 174: ...174 Summit 300 48 Switch Software User Guide Supported Standards...