Configure AAA Policy Server RADIUS Settings

Before you begin

An AAA policy must exist. See AAA Policy Configuration.

About this task

Configure or edit RADIUS server settings:

Procedure

  1. Choose from the following actions:
    1. To continue configuring settings for a new AAA policy, skip to step 2.
    2. To edit RADIUS server settings, select Policy > AAA, then select an existing policy from the list in the AAA pane to open the configuration window.
  2. Configure or edit the following RADIUS server Settings:
    Radius settings Description
    Accounting type Select the accounting type to specify the frequency of event notifications. Options include:
    • Start/Stop — Sends a start accounting notice at the beginning of a process and a stop notice at the end of a process. The start accounting record is sent in the background. The requested process begins regardless of whether the start accounting notice is received by the accounting server.
    • Start/Interim/Stop — Sends a start accounting notice at the beginning of a process, multiple regular notices while a process is running, and a stop notice at the end of a process.
    • Stop Only — Sends only a stop notice at the end of a process.

    The default option is Start/Stop

    Address format Specify the format in which the MAC address must be filled in the Radius-Request frames. Options include:
    • No Delimiter (AABBCCDDEEFF)
    • Colon Delimiter (AA:BB:CC:DD:EE:FF)
    • Hyphen Delimiter (AA-BB-CC-DD-EE-FF)
    • Space Delimiter (AA BB CC DD EE FF)
    • Dot Delimiter per Four (AABB.CCDD.EEFF)
    • Middle Hyphen Delimiter (AABBCC-DDEEFF)

    The default option is Hyphen Delimiter (AA-BB-CC-DD-EE-FF)

    Case Specify the Case of the MAC address that must be filled in Radius-Request frames:
    • Upper
    • Lower

    The default option is Upper.

    Attributes Specify the RADIUS attributes to which the MAC address format is applicable:
    • All — Applies to all attributes with MAC addresses such as username, password, calling-station-id, and called-station-id
    • Username-Password — Applies only to the username and password fields.

    The default option is Username-Password.

    Server pooling The server pooling mode controls how requests are transmitted across RADIUS servers.

    Selecting Fail Over results in working down the list of servers if a server is unresponsive and unavailable.

    Selecting the Load-Balance option results in all available servers transmitting requests in round robin mode.

    The default option is Fail Over.

    Authentication Protocol Options include:
    • PAP
    • CHAP
    • MS-CHAP
    • MS-CHAPv2

    The default protocol option is PAP

  3. After you have completed configuring the settings, choose from the following actions:
    1. Select Apply to commit the configured settings.
      Note

      Note

      This does not save the settings you configured; it provides a preview of your applied settings. To undo the settings you applied, select Revert.
    2. Select Save to commit and save the configured settings.
      Note

      Note

      If you do not select Save, the settings that you configured are not saved when you move away from the configuration window.