Purpose
Command or Action
The range for
tries
is from 1 to 100. The switch dynamically determines the
default
tries
parameter that is 10 to 100.
dead-criteria time 30 tries 20
(Optional) Sets the number of minutes that a RADIUS server is not sent
requests. The range is from 0 to 1440 minutes (24 hours). The default is 0
minutes.
radius-server deadtime minutes
Example:
Switch(config)#
radius-server
Step 3
deadtime 60
(Optional) Configures the RADIUS server parameters by using these keywords:
radius-server host ip-address
[
acct-port
udp-port
] [
auth-port udp-port
][
test
Step 4
•
acct-port udp-port
—
Specifies the UDP port for the RADIUS accounting
server. The range for the UDP port number is from 0 to 65536. The default
is 1646.
username name
[
idle-time time
]
[
ignore-acct-port
] [
ignore-auth-port
]]
[
key string
]
Example:
Switch(config)#
radius-server host
•
auth-port udp-port
—
Specifies the UDP port for the RADIUS
authentication server. The range for the UDP port number is from 0 to
65536. The default is 1645.
You should configure the UDP port for the RADIUS accounting
server and the UDP port for the RADIUS authentication server
to nondefault values.
Note
1.1.1.2 acct-port 1550 auth-port
1560 test username user1 idle-time
30 key abc1234
•
test username name
—
Enables automated testing of the RADIUS server
status, and specify the username to be used.
•
idle-time time
—
Sets the interval of time in minutes after which the switch
sends test packets to the server. The range is from 1 to 35791 minutes.
The default is 60 minutes (1 hour).
•
ignore-acct-port
—
Disables testing on the RADIUS-server accounting
port.
•
ignore-auth-port
—
Disables testing on the RADIUS-server authentication
port.
•
For
key string
, specify the authentication and encryption key used between
the switch and the RADIUS daemon running on the RADIUS server.
The key is a text string that must match the encryption key used on the
RADIUS server.
Always configure the key as the last item in the
radius-server
host
command syntax because leading spaces are ignored, but
spaces within and at the end of the key are used. If you use spaces
in the key, do not enclose the key in quotation marks unless the
quotation marks are part of the key. This key must match the
encryption used on the RADIUS daemon.
You can also configure the authentication and encryption key
by using the
radius-server key
{
0 string
|
7 string
|
string
} global
configuration command.
Note
Catalyst 2960-XR Switch Security Configuration Guide, Cisco IOS Release 15.0(2)EX1
OL-29434-01
275
Configuring IEEE 802.1x Port-Based Authentication
Configuring the Inaccessible Authentication Bypass Feature