Configure External RADIUS Server Settings

You must first create a wireless network SSID with Enterprise 802.1X access security. This option requires users to authenticate by entering a user name and password, which are checked against a RADIUS authentication server.

If in the process of configuring RADIUS server settings, you discover you need to add an external RADIUS server, use this task. You will need the IP address, authentication port number, and the shared secret for the RADIUS server.

This task is part of creating or editing a network policy. Use this task to configure a RADIUS server in the Configure RADIUS Servers window.

  1. Go to Configure > Network Policies.
  2. Select an existing policy and then select Edit, or select Add to create a new policy.
  3. On the Wireless tab, select Select and select an existing SSID, or select Add.
  4. Configure a RADIUS server group.
    1. Type the RADIUS Server Group Name.
    2. Optional: Type the RADIUS Server Group Description.
  5. Select EXTERNAL RADIUS SERVER.
  6. Select Select and select an existing server, or select Add.
  7. Type a Name for the server.
  8. Type an optional Description.
  9. Select the IP/Host Name for the RADIUS server.
    If you do not see the IP address that you need, select Add to define a new one (IPv4 or IPv6).

    If the address object is a host name, make sure that the devices are able to resolve it to an IP address. If you configure a domain name for the devices, or if the devices dynamically receive a domain name through DHCP, and the RADIUS server belongs to the same domain, the RADIUS server name can be just the host name without the domain name. If the RADIUS server belongs to a different domain, the address object must be the fully qualified domain name (FQDN): the host name + the domain name.

  10. For Server Type, choose the RADIUS server role:
    • Authentication: As an authentication server, the RADIUS service requests that the client device demonstrate its identity.
    • Port: Set the RADIUS authentication port.
    • Accounting: As an accounting server, the RADIUS service tracks client-server session details.
    • Port: Set the RADIUS accounting port number.
  11. Type the Shared Secret for authenticating communications with the RADIUS server.
  12. Optional: Select Show Password.
  13. Select SAVE EXTERNAL RADIUS.

Continue the network policy configuration.