
Foundry Switch and Router Installation and Configuration Guide
3 - 36
December 2000
RADIUS Configuration Considerations
•
You must deploy at least one RADIUS server in your network.
•
Foundry devices support authentication using up to eight RADIUS servers. The device tries to use the
servers in the order you add them to the device’s configuration. If one RADIUS server is not responding, the
Foundry device tries the next one in the list.
•
You can select only one primary authentication method for each type of access to a device (CLI through
Telnet, CLI Privileged EXEC and CONFIG levels). For example, you can select RADIUS as the primary
authentication method for Telnet CLI access, but you cannot also select authentication as the
primary method for the same type of access. However, you can configure backup authentication methods for
each access type.
RADIUS Configuration Procedure
Use the following procedure to configure a Foundry device for RADIUS:
1.
Configure Foundry vendor-specific attributes on the RADIUS server. See “Configuring Foundry-Specific
Attributes on the RADIUS Server” on page 3-36.
2.
Identify the RADIUS server to the Foundry device. See “Identifying the RADIUS Server to the Foundry
Device” on page 3-37.
3.
Set RADIUS parameters. See “Setting RADIUS Parameters” on page 3-38.
4.
Configure authentication-method lists. See “Configuring Authentication-Method Lists for RADIUS” on page 3-
38.
5.
Optionally configure RADIUS authorization. See “Configuring RADIUS Authorization” on page 3-40.
6.
Optionally configure RADIUS accounting. “Configuring RADIUS Accounting” on page 3-40.
Configuring Foundry-Specific Attributes on the RADIUS Server
During the RADIUS authentication process, if a user supplies a valid username and password, the RADIUS server
sends an Access-Accept packet to the Foundry device, authenticating the user. Within the Access-Accept packet
are three Foundry vendor-specific attributes that indicate:
•
The privilege level of the user
•
A list of commands
•
Whether the user is allowed or denied usage of the commands in the list
You must add these three Foundry vendor-specific attributes to your RADIUS server’s configuration, and
configure the attributes in the individual or group profiles of the users that will access the Foundry device.
Summary of Contents for Switch and Router
Page 2: ...December 2000 Copyright 2000 by Foundry Networks Inc ...
Page 26: ...Foundry Switch and Router Installation and Configuration Guide xxvi December 2000 ...
Page 64: ...Foundry Switch and Router Installation and Configuration Guide 2 34 December 2000 ...
Page 162: ...Foundry Switch and Router Installation and Configuration Guide 5 38 December 2000 ...
Page 196: ...Foundry Switch and Router Installation and Configuration Guide 6 34 December 2000 ...
Page 208: ...Foundry Switch and Router Installation and Configuration Guide 7 12 December 2000 ...
Page 236: ...Foundry Switch and Router Installation and Configuration Guide 8 28 December 2000 ...
Page 258: ...Foundry Switch and Router Installation and Configuration Guide 9 22 December 2000 ...
Page 420: ...Foundry Switch and Router Installation and Configuration Guide 13 32 December 2000 ...
Page 442: ...Foundry Switch and Router Installation and Configuration Guide 14 22 December 2000 ...
Page 554: ...Foundry Switch and Router Installation and Configuration Guide 15 112 December 2000 ...
Page 574: ...Foundry Switch and Router Installation and Configuration Guide 16 20 December 2000 ...
Page 626: ...Foundry Switch and Router Installation and Configuration Guide 17 52 December 2000 ...
Page 682: ...Foundry Switch and Router Installation and Configuration Guide 18 56 December 2000 ...
Page 826: ...Foundry Switch and Router Installation and Configuration Guide 20 20 December 2000 ...
Page 994: ...Foundry Switch and Router Installation and Configuration Guide 26 10 December 2000 ...
Page 1004: ...Foundry Switch and Router Installation and Configuration Guide B 6 December 2000 ...
Page 1044: ...Foundry Switch and Router Installation and Configuration Guide C 40 December 2000 ...
Page 1048: ...Foundry Switch and Router Installation and Configuration Guide D 4 December 2000 ...
Page 1070: ...Foundry Switch and Router Installation and Configuration Guide Index 18 December 2000 ...