02.10.2013 Views

FTOS Configuration Guide for the C-Series - Force10 Networks

FTOS Configuration Guide for the C-Series - Force10 Networks

FTOS Configuration Guide for the C-Series - Force10 Networks

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

<strong>Configuration</strong> Task List <strong>for</strong> RADIUS<br />

To au<strong>the</strong>nticate users using RADIUS, at least one RADIUS server must be specified so that <strong>the</strong> system can<br />

communicate with and configure RADIUS as one of your au<strong>the</strong>ntication methods.<br />

The following list includes <strong>the</strong> configuration tasks <strong>for</strong> RADIUS.<br />

• Defining a aaa method list to be used <strong>for</strong> RADIUS on page 147 (mandatory)<br />

• Applying <strong>the</strong> method list to terminal lines on page 148 (mandatory except when using default lists)<br />

• Specifying a RADIUS server host on page 148 (mandatory)<br />

• Setting global communication parameters <strong>for</strong> all RADIUS server hosts on page 149 (optional)<br />

• Monitoring RADIUS on page 150 (optional)<br />

For a complete listing of all <strong>FTOS</strong> commands related to RADIUS, refer to <strong>the</strong> Security chapter in <strong>the</strong><br />

<strong>FTOS</strong> Command Reference.<br />

Note: RADIUS au<strong>the</strong>ntication and authorization are done in a single step. Hence, authorization cannot be<br />

used independent of au<strong>the</strong>ntication. However, if RADIUS authorization is configured and au<strong>the</strong>ntication is<br />

not, <strong>the</strong>n a message is logged stating this. During authorization, <strong>the</strong> next method in <strong>the</strong> list (if present) is<br />

used, or if ano<strong>the</strong>r method is not present, an error is reported.<br />

To view <strong>the</strong> configuration, use <strong>the</strong> show config in <strong>the</strong> LINE mode or <strong>the</strong> show running-config command<br />

in <strong>the</strong> EXEC privilege mode.<br />

Defining a AAA method list to be used <strong>for</strong> RADIUS<br />

To configure RADIUS to au<strong>the</strong>nticate or authorize users on <strong>the</strong> system, you must create a AAA method<br />

list. Default method lists do not need to be explicitly applied to <strong>the</strong> line, so <strong>the</strong>y are not mandatory. To<br />

create a method list, enter one of <strong>the</strong> following commands in CONFIGURATION mode:<br />

Command Syntax Command Mode Purpose<br />

aaa au<strong>the</strong>ntication login<br />

method-list-name radius<br />

aaa authorization exec<br />

{method-list-name | default} radius<br />

tacacs+<br />

CONFIGURATION Enter a text string (up to 16 characters long) as <strong>the</strong><br />

name of <strong>the</strong> method list you wish to use with <strong>the</strong><br />

RADIUS au<strong>the</strong>ntication method.<br />

CONFIGURATION Create methodlist with RADIUS and TACACS+ as<br />

authorization methods. Typical order of methods:<br />

RADIUS, TACACS+, Local, None. If authorization<br />

is denied by RADIUS, <strong>the</strong> session ends (radius<br />

should not be <strong>the</strong> last method specified).<br />

<strong>FTOS</strong> <strong>Configuration</strong> <strong>Guide</strong>, version 7.7.1.0 147

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!