13-6
Cisco IOS Software Configuration Guide for Cisco Aironet Access Points
OL-14209-01
Chapter 13 Configuring RADIUS and Servers
Configuring and Enabling RADIUS
Step 3
radius-server host
{
hostname
|
ip-address
} [
auth-port
port-number
]
[
acct-port
port-number
] [
timeout
seconds
] [
retransmit
retries
] [
key
string
]
Specify the IP address or host name of the remote RADIUS server host.
•
(Optional) For
auth-port
port-number
, specify the UDP destination
port for authentication requests. The default port number is 1645 if
this parameter is not present.
•
(Optional) For
acct-port
port-number
, specify the UDP destination
port for accounting requests. The default port number is 1646 if this
parameter is not present.
•
(Optional) For
timeout
seconds
, specify the time interval that the
access point waits for the RADIUS server to reply before
retransmitting. The range is 1 to 1000. This setting overrides the
radius-server timeout
global configuration command setting. If no
timeout is set with the
radius-server host
command, the setting of
the
radius-server timeout
command is used.
•
(Optional) For
retransmit
retries
, specify the number of times a
RADIUS request is resent to a server if that server is not responding
or responding slowly. The range is 1 to 1000. If no retransmit value
is set with the
radius-server host
command, the setting of the
radius-server retransmit
global configuration command is used.
•
(Optional) For
key
string
, specify the authentication and encryption
key used between the access point and the RADIUS daemon running
on the RADIUS server.
Note
The key is a text string that must match the encryption key used
on the RADIUS server. Always configure the key as the last item
in the
radius-server host
command. Leading spaces are ignored,
but spaces within and at the end of the key are used. If you use
spaces in your key, do not enclose the key in quotation marks
unless the quotation marks are part of the key.
To configure the access point to recognize more than one host entry
associated with a single IP address, enter this command as many times as
necessary, making sure that each UDP port number is different. The
access point software searches for hosts in the order in which you specify
them. Set the timeout, retransmit, and encryption key values to use with
the specific RADIUS host.
Step 4
dot11 ssid
ssid-string
Enter SSID configuration mode for an SSID on which you need to enable
accounting. The SSID can consist of up to 32 alphanumeric characters.
SSIDs are case sensitive.
Command
Purpose