02.10.2013 Views

FTOS Configuration Guide for the C-Series - Force10 Networks

FTOS Configuration Guide for the C-Series - Force10 Networks

FTOS Configuration Guide for the C-Series - Force10 Networks

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Applying <strong>the</strong> method list to terminal lines<br />

To enable RADIUS AAA login au<strong>the</strong>ntication <strong>for</strong> a method list, you must apply it to a terminal line. To<br />

configure a terminal line <strong>for</strong> RADIUS au<strong>the</strong>ntication and authorization, enter <strong>the</strong> following commands:<br />

Command Syntax Command Mode Purpose<br />

line {aux 0 | console 0 | vty number<br />

[end-number]}<br />

login au<strong>the</strong>ntication<br />

{method-list-name | default}<br />

Specifying a RADIUS server host<br />

CONFIGURATION Enter <strong>the</strong> LINE mode.<br />

LINE Enable AAA login au<strong>the</strong>ntication <strong>for</strong> <strong>the</strong> specified<br />

RADIUS method list. This procedure is<br />

mandatory if you are not using default lists.<br />

authorization exec methodlist CONFIGURATION To use <strong>the</strong> methodlist.<br />

When configuring a RADIUS server host, you can set different communication parameters, such as <strong>the</strong><br />

UDP port, <strong>the</strong> key password, <strong>the</strong> number of retries, and <strong>the</strong> timeout.<br />

To specify a RADIUS server host and configure its communication parameters, use <strong>the</strong> following<br />

command in <strong>the</strong> CONFIGURATION mode:<br />

Command Syntax Command Mode Purpose<br />

radius-server host {hostname |<br />

ip-address} [auth-port<br />

port-number] [retransmit retries]<br />

[timeout seconds] [key<br />

[encryption-type] key]<br />

CONFIGURATION Enter <strong>the</strong> host name or IP address of <strong>the</strong> RADIUS<br />

server host. Configure <strong>the</strong> optional communication<br />

parameters <strong>for</strong> <strong>the</strong> specific host:<br />

• auth-port port-number range: 0 to 65335. Enter<br />

a UDP port number. The default is 1812.<br />

• retransmit retries range: 0 to 100. Default is 3.<br />

• timeout seconds range: 0 to 1000. Default is 5<br />

seconds.<br />

• key [encryption-type] key: Enter 0 <strong>for</strong> plain text<br />

or 7 <strong>for</strong> encrypted text, and a string <strong>for</strong> <strong>the</strong> key.<br />

The key can be up to 42 characters long. This<br />

key must match <strong>the</strong> key configured on <strong>the</strong><br />

RADIUS server host.<br />

If <strong>the</strong>se optional parameters are not configured, <strong>the</strong><br />

global default values <strong>for</strong> all RADIUS host are<br />

applied.<br />

To specify multiple RADIUS server hosts, configure <strong>the</strong> radius-server host command multiple times. If<br />

multiple RADIUS server hosts are configured, <strong>FTOS</strong> attempts to connect with <strong>the</strong>m in <strong>the</strong> order in which<br />

<strong>the</strong>y were configured. When <strong>FTOS</strong> attempts to au<strong>the</strong>nticate a user, <strong>the</strong> software connects with <strong>the</strong><br />

RADIUS server hosts one at a time, until a RADIUS server host responds with an accept or reject<br />

response.<br />

148 Security

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!