Defining RADIUS Servers for VNS Global Settings

To define RADIUS servers for VNS global settings:

  1. From the top menu, click VNS.
  2. In the left pane, click Global > Authentication.
  3. Select Strict Mode to force the top three Radius servers in priority order for each WLAN (Wireless Local Area Network) where applicable. Clearing this check box, allows individual Radius change per WLAN.
    Click to expand in new window
    Global Authentication Settings
    Graphics/Radius_Server_MacAddress_update2.png
  4. To define a new RADIUS server available on the network, click New. The RADIUS Settings dialog displays.
    Click to expand in new window
    RADIUS Server Settings
    Graphics/Radius_Server_settings2.png
  5. In the Server Alias field, type a name that you want to assign to the RADIUS server.
    Note

    Note

    You can also type the RADIUS server‘s IP address in the Server Alias box in place of a nickname. The RADIUS server will identify itself by the value typed in the Server Alias box in the RADIUS Servers drop down list on the RADIUS Authentication tab of the Login Management screen (top menu > Wireless Controller > Login Management). For more information, see Configuring the Login Authentication Mode.
  6. In the Hostname/IP field, type either the RADIUS server‘s FQDN (fully qualified domain name) or IP address.
    Note

    Note

    If you type the host name in the Hostname/IP address box, the controller will send a host name query to the DNS server for host name resolution. The DNS servers must be appropriately configured for resolving the RADIUS servers‘ host names. For more information, see Configuring DNS Servers for Resolving Host Names of NTP and RADIUS Servers.
  7. In the Shared Secret field, type the password that will be used to validate the connection between the controller and the RADIUS server.

    To proofread your shared secret key, click Unmask. The password is displayed.

    Note

    Note

    You should always proofread your Shared Secret key to avoid any problems later when the controller attempts to communicate with the RADIUS server.
  8. If desired, change the Default Protocol using the drop down list. Choices are PAP, CHAP, MS-CHAP, or MS-CHAP2.
  9. If desired, change the pre-defined default values for Authentication and Accounting operations:
    1. Priority — default is 4.
    2. Total number of tries — default is 3.
    3. RADIUS Request timeout — default is 5 seconds.
    4. For Accounting operations, the Interim Accounting Interval — default is 30 minutes. Setting the Interim Accounting Interval value to 0 results in no interims being sent.
    5. Port — default Authentication port is 1812. Default Accounting port is 1813.
  10. If desired, setup Health Monitoring by selecting a Polling Mechanism from the drop-down menu, and enter a Test Request Timeout (shown in seconds).
  11. To save your changes, click Save. The new server is displayed in the RADIUS Servers list.
    Note

    Note

    The RADIUS server is identified by its Server Alias.
  12. To edit an existing server, click the row containing the server. The RADIUS Settings window displays, containing the server‘s configuration values.
  13. To remove a server from the list, select the checkbox next to the server, and then click Delete Selected. You cannot remove a server that is used by any VNS.