Configuring Security
Configuring RADIUS Servers
Cisco 220 Series Smart Switches Administration Guide Release 1.1.0.x
191
16
Configuring RADIUS Servers
An organization can establish a Remote Authorization Dial-In User Service
(RADIUS) server to provide a centralized 802.1X or MAC-based network access
control for all of its devices. The switch can act as a RADIUS client that uses the
RADIUS server to provide centralized security, authorization, and user
authentication.
To use a RADIUS server, you should open an account for the switch on the RADIUS
server, and configure that RADIUS server along with the other parameters on the
RADIUS page.
NOTE
If more than one RADIUS server has been configured, the switch uses the
configured priorities of the available RADIUS servers to select the RADIUS server
to be used by the switch.
To define the default RADIUS parameters and add a RADIUS server:
STEP 1
Click
Security
>
RADIUS
.
STEP 2
In the
Use Default Parameters
area, enter the default RADIUS parameters that
are applied to all RADIUS servers. If a value is not entered for a specific server, the
switch uses the values in these fields.
•
Retries
—Enter the number of transmitted requests that are sent to the
RADIUS server before a failure is considered to have occurred.
•
Timeout for Reply
—Enter the number of seconds that the switch waits for
an answer from the RADIUS server before retrying the query, or switching to
the next server.
•
Key String
—The key string is used to encrypt communications between the
switch and the RADIUS server by using MD5. Enter the default key string in
encrypted or plaintext form. This key must match the key configured on the
RADIUS server. If you do not have an encrypted key string (from another
device), enter the key string in plaintext form.
STEP 3
Click
Apply
. The default RADIUS parameters are defined, and the Running
Configuration is updated.
STEP 4
To add a RADIUS server, click
Add
.
STEP 5
Enter the following information:
•
Server Definition
—Select whether to specify the RADIUS server by IP
address or name.