This object provides an option for configuring users on a remote RADIUS server and authenticating login attempts with that RADIUS server. The authenticating user should be part of the Administrator group.
For configuration details, see Configuring SBC for RADIUS Authentication best practice.
The CLI syntax to configure RADIUS-based authentication is shown below.
% set oam radiusAuthentication radiusServer <server name> mgmtInterfaceGroup <string> priority <#> radiusNasIp <x.x.x.x> radiusServerIp <x.x.x.x> radiusServerPort <#> radiusSharedSecret <8-128> state <disabled | enabled> retryCriteria oosDuration <# minutes> retryCount <#> retryTimer <# milliseconds>
Parameter | Description |
---|---|
radiusServer | Use this object to configure each RADIUS server for the specified Management Interface Group.
IPv6 configuration for RADIUS server is not supported at this time. In a SBC HA configuration, four management IP addresses must be listed on the RADIUS server:
|
| Use this parameter to configure SBC's authentication retry criteria before timing out, as well as RADIUS server out-of-service setting.
|
The following example configures
% set oam radiusAuthentication radiusServer s1 % set oam radiusAuthentication radiusServer s1 priority 1 % set oam radiusAuthentication radiusServer s1 mgmtInterfaceGroup mgmt0 % set oam radiusAuthentication radiusServer s1 radiusServerIp 10.54.90.107 % set oam radiusAuthentication radiusServer s1 radiusServerPort 1812 % set oam radiusAuthentication radiusServer s1 radiusSharedSecret sonus123 % set oam radiusAuthentication radiusServer s1 state enabled % set oam radiusAuthentication retryCriteria oosDuration 120 % set oam radiusAuthentication retryCriteria retryCount 2 % set oam radiusAuthentication retryCriteria retryTimer 2000
The radiusSharedSecret
results in the 'show' command will be encrypted.
The following example enables external RADIUS authentication:
% set system admin TXSBC01a externalAuthenticationEnabled true