Configuring Settings For All Radius Servers - Cisco ONS 15454 SDH Configuration Manual

Hide thumbs Also See for ONS 15454 SDH:
Table of Contents

Advertisement

Chapter 19 Configuring Security for the ML-Series Card
Identifying the specific ML-Series card that sent the request to the server can be useful in debugging
from the server. The nas-ip-address is primarily used for validation of the RADIUS authorization and
accounting requests.
If this value is not configured, the nas-ip-address is filled in by the normal Cisco IOS mechanism using
the value configured by the ip radius-source command. If no value is specified then the best IP address
routable to the server is used. If no routable address is available, the IP address of the server is used.
Beginning in privileged EXEC mode, follow these steps to configure the nas-ip-address:
Command
Step 1
Router# configure terminal
Step 2
Router (config)# [no] ip radius
nas-ip-address { hostname |
ip-address }
Step 3
Router (config)# end
Step 4
Router# show running-config
Step 5
Router# copy running-config
startup-config

Configuring Settings for All RADIUS Servers

Beginning in privileged EXEC mode, follow these steps to configure global communication settings
between the ML-Series card and all RADIUS servers:
Command
Step 1
Router# configure terminal
Step 2
Router (config)# radius-server
key string
Step 3
Router (config)# radius-server
retransmit retries
Step 4
Router (config)# radius-server
timeout seconds
Purpose
Enter global configuration mode.
Specify the IP address or hostname of the attribute 4 (nas-ip-address) in the
radius packet.
If there is only one ML-Series card in the ONS node, this command does
not provide any advantage. The public IP address of the ONS node serves
as the nas-ip-address in the RADIUS packet sent to the server.
Return to privileged EXEC mode.
Verify your settings.
(Optional) Save your entries in the configuration file.
Purpose
Enter global configuration mode.
Specify the shared secret text string used between the ML-Series card and
all RADIUS servers.
Note
Specify the number of times the ML-Series card sends each RADIUS
request to the server before giving up. The default is 3; the range 1 to 1000.
Specify the number of seconds a ML-Series card waits for a reply to a
RADIUS request before resending the request. The default is 5 seconds; the
range is 1 to 1000.
Cisco ONS 15454 and Cisco ONS 15454 SDH Ethernet Card Software Feature and Configuration Guide, R8.0
The key is a text string that must match the encryption key used on
the RADIUS server. Leading spaces are ignored, but spaces within
and at the end of the key are used. If you use spaces in your key, do
not enclose the key in quotation marks unless the quotation marks
are part of the key.
Configuring RADIUS
19-17

Advertisement

Table of Contents
loading

This manual is also suitable for:

Ons 15454

Table of Contents