S e n d d o c u m e n t a t i o n c o m m e n t s t o m d s f e e d b a c k - d o c @ c i s c o . c o m
32-10
Cisco MDS 9000 Family CLI Configuration Guide
OL-16184-01, Cisco MDS SAN-OS Release 3.x
Chapter 32 Configuring RADIUS and
Configuring RADIUS
About the Default RADIUS Server Encryption Type and Preshared Key
You need to configure the RADIUS preshared key to authenticate the switch to the RADIUS server. The
length of the key is restricted to 64 characters and can include any printable ASCII characters (white
spaces are not allowed). You can configure a global key to be used for all RADIUS server configurations
on the switch.
You can override this global key assignment by explicitly using the
key
option in the
radius-server host
command.
Configuring the Default RADIUS Server Encryption Type and Preshared Key
To configure the RADIUS preshared key, follow these steps:
Step 3
switch(config)# r
adius-server host radius2
auth-port 2003
Specifies the destination UDP port number to
which the RADIUS authentication messages
should be sent. In this example, the host is
radius2 and the authentication port is 2003. The
default authentication port is 1812, and the valid
range is 0 to 65366.
Step 4
switch(config)#
radius-server host radius2
acct-port 2004
Specifies the destination UDP port number to
which RADIUS accounting messages should be
sent. The default accounting port is 1813, and
the valid range is 0 to 65366.
Step 5
switch(config)#
radius-server host radius2
accounting
Specifies this server to be used only for
accounting purposes.
Note
If neither the
authentication
nor the
accounting
options are specified, the
server is used for both accounting and
authentication purposes.
Step 6
switch(config)#
radius-server host radius2
key 0 abcd
Specifies a clear text key for the specified
server. The key is restricted to 64 characters.
switch(config)#
radius-server host radius2
key 4 da3Asda2ioyuoiuH
Specifies an encrypted key for the specified
server. The key is restricted to 64 characters.
Command
Purpose
Command
Purpose
Step 1
switch#
config t
Enters configuration mode.