show radius

Display the global status of Remote Access Dial-In User Services (RADIUS) information.

Syntax

Default

None

Command Mode

User EXEC

Command Output

The show radius command displays the following information:

Output field

Description

acct-attribute-value

Specifies the accounting attribute value.

acct-enable

Specifies if the accounting attribute is enabled.

acct-include-cli-commands

Specifies if the accounting attribute includes CLI commands. The default is false.

access-priority-attribute

Specifies the value of the access priority attribute. The default is 192.

auth-info-attr-value

Specifies the value of the authentication information attribute. The default is 91.

command-access-attribute

Specifies the value of the command access attribute. The default is 194.

cli-commands-attribute

Specifies the value of the CLI commands attribute. The default is 195.

cli-cmd-count

Specifies how many CLI commands before the system sends a RADIUS accounting interim request. The default is 40.

cli-profile-enable

Specifies if RADIUS CLI profiling is enabled. CLI profiling grants or denies access to users being authenticated by way of the RADIUS server. You can add a set of CLI commands to the configuration on the RADIUS server, and you can specify the command-access mode for these commands. The default is false.

enable

Specifies if RADIUS authentication is globally enabled on the switch.

igap-passwd-attr

Specifies the IGMP for user Authentication Protocol (IGAP) password attribute.

igap-timeout-log-fsize

Specifies the IGMP for user Authentication Protocol (IGAP) timeout log file size.

maxserver

Specifies the maximum number of servers allowed for the device. The default is 10.

mcast-addr-attr-value

Specifies the value of the multicast address attribute. The default is 90.

secure-flag

Specifies whether RADIUS Security (RADSec) is globally enabled. The default is disabled.

sourceip-flag

Note:

Exception: only supported on VSP 8600 Series.

Specifies if the switch can use a configured source IP address. If the outgoing interface on the switch fails, a different source IP address is used, which requires that you make configuration changes to define the new RADIUS client on the RADIUS server. To simplify RADIUS server configuration, you can configure the switch to use a circuitless IP (CLIP) address as the source IP and NAS IP address when transmitting RADIUS packets.

By default, the switch uses the IP address of the outgoing interface as the source IP, and the NAS IP address for RADIUS packets that it transmits.