Cisco 4700M Configuration Manual page 99

Application control engine appliance security
Hide thumbs Also See for 4700M:
Table of Contents

Advertisement

Chapter 2
Configuring Authentication and Accounting Services
Configuring the Global RADIUS Server Dead-Time Interval
OL-16202-01
Configuring the ACE as a Client of a RADIUS, TACACS+, or LDAP Server
The syntax of this command is as follows:
radius-server key {shared_secret | 0 shared_secret | 7 shared_secret}
The arguments and keywords are as follows:
shared_secret—Key used to authenticate communication between the
RADIUS client and server. The shared secret must match the one configured
on the RADIUS server. Enter the shared secret as a case-sensitive string with
no spaces and a maximum of 63 alphanumeric characters.
0—Configures a key specified in clear text (indicated by 0) to authenticate
communication between the RADIUS client and server.
7—Configures a key specified in encrypted text (indicated by 7) to
authenticate communication between the RADIUS client and server.
For example, to globally configure an authentication key to be sent in encrypted
text (indicated by 7) to the RADIUS server, enter:
host1/Admin(config)# radius-server key 7 abe4DFeeweo00o
To delete the key, enter:
host1/Admin(config)# no radius-server key 7 abe4DFeeweo00o
During the dead-time interval, the ACE sends probe access-request packets to
verify that the RADIUS server is available and can receive authentication
requests. The dead-time interval starts when the server does not respond to the
number of authentication request transmissions configured through either the
radius-server retransmit command or the radius-server host retransmit
command. When the server responds to a probe access-request packet, the ACE
transmits the authentication request to the server.
Use the radius-server deadtime command to globally set the time interval in
which the ACE verifies whether a nonresponsive server is operational.
This command causes the ACE to mark any RADIUS servers that fail to respond
to authentication requests as dead. This action avoids the wait for the request to
time out before trying the next configured server. The ACE skips a RADIUS
server that is marked as dead by sending additional requests for the duration of the
specified minutes argument.
Cisco 4700 Series Application Control Engine Appliance Security Configuration Guide
2-29

Advertisement

Table of Contents
loading

This manual is also suitable for:

4700 series

Table of Contents