RADIUS Settings
157
Click
Apply
to update the switch configuration. Your changes take effect immediately but are not
retained across a switch reset unless you click
Save Configuration
.
Max Number of
Retransmits
The maximum number of times the RADIUS client on the device will retransmit a request
packet to a configured RADIUS server after a response is not received. If multiple RADIUS
servers are configured, the max retransmit value will be exhausted on the first server before
the next server is attempted. A retransmit will not occur until the configured timeout value on
that server has passed without a response from the RADIUS server. Therefore, the maximum
delay in receiving a response from the RADIUS server equals the sum of (retransmit ×
timeout) for all configured servers. If the RADIUS request was generated by a user login
attempt, all user interfaces will be blocked until the RADIUS application returns a response.
Timeout Duration
The number of seconds the RADIUS client waits for a response from the RADIUS server.
Consideration to maximum delay time should be given when configuring RADIUS timeout
and RADIUS max retransmit values.
NAS-IP Address
The network access server (NAS) IP address for the RADIUS server. To specify an address,
click the
Edit
icon and enter the IP address of the NAS in the available field. The address
should be unique to the NAS within the scope of the RADIUS server. The NAS IP address is
used only in Access-Request packets. To reset the NAS IP address to the default value, click
the Reset icon and confirm the action.
RADIUS Server Information
Current
Identifies whether the configured RADIUS server is the current server for the authentication
server group.
True—The server is the current server for the authentication server group.
False—The server is a secondary server.
When the switch sends a RADIUS request to the named server, the request is directed to the
server selected as the current server. Initially the primary server is selected as the current
server. If the primary server fails, one of the other servers becomes the current server. If more
than one RADIUS server is configured with the same name, the switch selects one of the
servers to be the current server from the group of servers with the same name.
RADIUS Server Name
Shows the RADIUS server name. Multiple RADIUS servers can have the same name. In this
case, RADIUS clients can use RADIUS servers with the same name as backups for each
other.
IP Address/Host Name
The IP address or DNS name of the RADIUS server.
Port Number
Identifies the authentication port the server uses to verify the RADIUS server authentication.
The port is a UDP port.
Server Type
Shows whether the server is a Primary or Secondary server.
Secret Configured
Indicates whether the shared secret for this server has been configured. To reset the shared
secret to an unconfigured state, click the reset icon. To set a new password for the RADIUS
server, select the checkbox associated with the server and click Edit. Then, specify a shared
secret in the Secret field.
Message Authenticator
Shows whether the message authenticator attribute for the selected server is enabled or
disabled.
Secret
This field is available when you add or edit a RADIUS server. This is the shared secret text
string used for authenticating and encrypting all RADIUS communications between the
RADIUS client on the device and the RADIUS accounting server. The secret specified in this
field must match the shared secret configured on the RADIUS accounting server.
Field
Description