QTECH
Software Configuration Manual
16-211
16.5 Remote authentication configuration
16.5.1
Configure RADIUS to be remote authentication server
Configure RADIUS remote authentication
Operation
Command
Description
Enter global configuration
configure terminal
-
Enable RADIUS remote
authentication
muser radius name {chap|pap}
[local]
Selected
If “local“is configured, it means local
authentication is used if remote
authentication failed.
By default, it is local authentication
Enter AAA configuration mode
aaa
-
Create RADIUS server name and
enter RADIUS configuration mode
radius host
name
-
Configure IP of
authentication/accounting RADIUS
server
{primary-acct-ip |
primary-auth-ip }
A.B.C.D
{
accounting port
|
authentication port
}
Selected
Authentication and accounting port
should be the same as that of RADIUS
server. Generally, they are :
Accounting port : 1813
Authentication port : 1812
Configure shared-key of
authentication/accounting RADIUS
server
{acct-secret-key|
auth-secret-key}
key
Selected
Shared-key should be the same as that of
RADIUS server.
Show configuration
show muser
-
16.5.2
Configure remote authentication
Configuring user
’
s login through server authentication, accounting and authorization through
server can be chosen. When configuring authorization, configure corresponded priority to users first.
There are 16 levels (0-16) priorities but there are only 2 levels (0-1 means normal users and 2-15 means
administrators) for QTECH switches. When configuring unauthorization, the priority is determined by
priv_lvl replied from remote server (no reply means administrator). Authorization failure means normal user.
When configuring accounting, it begins with the pass of authentication and ends with user’s exit.
Configure remote authentication
Operation
Command
Description
Enable
authorization/accounting
muser {account [local] |author
[local]|local}
Selected
If “local“is configured, it means
local authentication is used if
remote authentication failed.
By default, it is local authentication
Configure
IP/shared-key/TCP
port/timeout of
remote server
{
priamary
|
secondary
}
server
ipaddress
[
key
keyvalue
] [
port
portnum
]
[
timeout
timevalue
]
Selected
By default, TCP port is 49 and
timeout is 5 seconds.
Show
configuration
show
-
Show
current
show muser
-