S e n d d o c u m e n t a t i o n c o m m e n t s t o m d s f e e d b a c k - d o c @ c i s c o . c o m
17-4
Cisco MDS 9000 Family Troubleshooting Guide, Release 3.x
OL-9285-05
Chapter 17 Troubleshooting RADIUS and
AAA Issues
Verifying RADIUS Configuration Using Fabric Manager
To verify or change the RADIUS configuration using Fabric Manager, follow these steps:
Step 1
Choose
Switches > Security > AAA > RADIUS
and select the
Servers
tab. You see the RADIUS
configuration in the Information pane.
Step 2
Highlight the server that you need to change and click
Delete Row
to delete this server configuration.
Step 3
Click
Create Row
to add a new RADIUS server.
Step 4
Set the KeyType and Key fields to the preshared key configured on the RADIUS server.
Step 5
Set the AuthPort and AcctPort fields to the authentication and accounting ports configured on the
RADIUS server.
Step 6
Set the TimeOut value and click
Apply
to save these changes.
Step 7
Select the
CFS
tab and select
commit
from the Config Action drop-down menu and click
Apply
Changes
to distribute these changes to all switches in the fabric.
Verifying RADIUS Configuration Using the CLI
To verify or change the RADIUS configuration using the CLI, follow these steps:
Step 1
Use the
show
radius-server
command to display configured RADIUS parameters.
switch#
show radius-server
Global RADIUS shared secret:
*******
retransmission count:5
timeout value:
10
following RADIUS servers are configured:
myradius.cisco.users.com:
available for authentication on port:
1812
available for accounting on port:
1813
10.1.1.1:
available for authentication on port:1812
available for accounting on port:1813
RADIUS shared secret:******
10.2.2.3:
available for authentication on port:1812
available for accounting on port:1813
RADIUS shared secret:******
Step 2
Use the
radius-server host
ip-address
key
command to
set the preshared key to match what is
configured on your RADIUS server.
Step 3
Use the
radius-server host
ip-address
auth-port
command to
set the authentication port to match what
is configured on your RADIUS server.
Step 4
Use the
radius-server host
ip-address
acc-port
command to
set the accounting port to match what is
configured on your RADIUS server.
Step 5
Use the
radius-server timeout
command to
set the
period in seconds for the switch to wait for a
response from all RADIUS servers before the switch declares a timeout failure.
Step 6
Use the
radius commit
command to commit any changes and distribute to all switches in the fabric.