RADIUS authentication
To add an authentication action for a RADIUS server by using the command line interface
add authentication radiusAction <name> [-serverip <IP> | -serverName] <FQDN>][-serverPort <port>] [-authTimeout <positive_integer>] {-radKey } [-radNASip ( ENABLED | DISABLED )][-radNASid <string>] [-radVendorID <positive_integer>][-radAttributeType <positive_integer>][-radGroupsPrefix <string>] [-radGroupSeparator <string>][-passEncoding <passEncoding>][-ipVendorID <positive_integer>] [-ipAttributeType <positive_integer>][-accounting ( ON | OFF )][-pwdVendorID <positive_integer> [-pwdAttributeType <positive_integer>]] [-defaultAuthenticationGroup <string>] [-callingstationid ( ENABLED | DISABLED )]
add authentication radiusaction Authn-Act-1 -serverip 10.218.24.65 -serverport 1812 -authtimeout 15 -radkey WareTheLorax -radNASip DISABLED -radNASid NAS1
Done
add authentication radiusaction Authn-Act-1 -serverName rad01.example.com -serverport 1812 -authtimeout 15 -radkey WareTheLorax -radNASip DISABLED -radNASid NAS1
Done
To configure an authentication action for an external RADIUS server by using the command line
set authentication radiusAction <name> [-serverip <IP> | -serverName] <FQDN>][-serverPort <port>] [-authTimeout <positive_integer>] {-radKey } [-radNASip ( ENABLED | DISABLED )][-radNASid <string>] [-radVendorID <positive_integer>][-radAttributeType <positive_integer>][-radGroupsPrefix <string>] [-radGroupSeparator <string>][-passEncoding <passEncoding>][-ipVendorID <positive_integer>] [-ipAttributeType <positive_integer>][-accounting ( ON | OFF )][-pwdVendorID <positive_integer> [-pwdAttributeType <positive_integer>]] [-defaultAuthenticationGroup <string>] [-callingstationid ( ENABLED | DISABLED )]
To remove an authentication action for an external RADIUS server by using the command line interface
rm authentication radiusAction <name>
rm authentication radiusaction Authn-Act-1
Done
To configure a RADIUS server by using the configuration utility
-
Navigate to Security > AAA - Application Traffic > Policies > Authentication > Radius
-
In the details pane, on the Servers tab, do one of the following:
-
To create a new RADIUS server, click Add.
-
To modify an existing RADIUS server, select the server, and then click Edit.
-
-
In the Create Authentication RADIUS Server or Configure Authentication RADIUS Server dialog, type or select values for the parameters. To fill out parameters that appear beneath Send Calling Station ID, expand Details.
-
Name*—radiusActionName (Cannot be changed for a previously configured action)
-
Authentication Type*—authtype (Set to RADIUS, cannot be changed)
-
Server Name / IP Address*—Choose either Server Name or Server IP
-
Server Name*—serverName \<FQDN\>
-
IP Address*—serverIp \<IP\> If the server is assigned an IPv6 IP address, select the IPv6 check box.
-
-
Port*—serverPort
-
Time-out (seconds)*—authTimeout
-
Secret Key*—radKey (RADIUS shared secret.)
-
Confirm Secret Key*—Type the RADIUS shared secret a second time. (No command line equivalent.)
-
Send Calling Station ID—callingstationid
-
Group Vendor Identifier—radVendorID
-
Group Attribute Type—radAttributeType
-
IP Address Vendor Identifier—ipVendorID
-
pwdVendorID—pwdVendorID
-
Password Encoding—passEncoding
-
Default Authentication Group—defaultAuthenticationGroup
-
NAS ID—radNASid
-
Enable NAS IP address extraction—radNASip
-
Group Prefix—radGroupsPrefix
-
Group Separator—radGroupSeparator
-
IP Address Attribute Type—ipAttributeType
-
Password Attribute Type—pwdAttributeType
-
Accounting—accounting
-
-
Click Create or OK. The policy that you created appears in the Servers page.
Support to pass through RADIUS attribute 66 (Tunnel-Client-Endpoint)
add authentication radiusAction <name> {-serverIP <ip_addr|ipv6_addr|*> | {-serverName <string>}} [-serverPort <port>] … [-tunnelEndpointClientIP (ENABLED|DISABLED)]
set radiusParams {-serverIP <ip_addr|ipv6_addr|*> |{-serverName <string>}} [-serverPort<port>] … [-tunnelEndpointClientIP(ENABLED|DISABLED)]
add authentication radiusAction radius -severIP 1.217.22.20 -serverName FQDN -serverPort 1812 -tunnelEndpointClientIp ENABLED
set radiusParams -serverIp 1.217.22.20 -serverName FQDN1 -serverPort 1812 -tunnelEndpointClientIP ENABLED
Support for validating end-to-end RADIUS authentication
-
Consolidates the complete flow (packet engine – aaa daemon – external server) to provide better analysis
-
Reduces time on validating and troubleshooting issues related to individual scenarios
From system option
-
Navigate to System > Authentication > Basic Policies > RADIUS, click Servers tab.
-
Select the available RADIUS action from the list.
-
On the Configure Authentication RADIUS Server page, you have two options under Connections Settings section.
-
To check the RADIUS server connection, click Test RADIUS Reachability tab.
-
To view the end-to-end RADIUS authentication, click Test End User Connection link.
From Authentication option
-
Navigate to Authentication > Dashboard, select the available RADIUS action from the list.
-
On the Configure Authentication RADIUS Server page, you have two options under Connections Settings section.
-
To check the RADIUS server connection, click Test RADIUS Reachability tab.
-
To view the end-to-end RADIUS authentication status, click Test End User Connection link.