Chapter 34
Configuring RADIUS and TACACS+
S e n d d o c u m e n t a t i o n c o m m e n t s t o m d s f e e d b a c k - d o c @ c i s c o . c o m
Command
Step 2
switch(config)# radius-server key AnyWord
switch(config)# radius-server key 0
AnyWord
switch(config)# radius-server key 7
abe4DFeeweo00o
Setting the RADIUS Server Timeout Interval
You can configure a global timeout value between transmissions for all RADIUS servers.
If timeout values are configured for individual servers, those values override the globally configured
Note
values.
To specify the timeout values between retransmissions to the RADIUS servers, follow these steps:
Command
Step 1
switch# config t
Step 2
switch(config)# radius-server
timeout 30
switch(config)# no radius-server
timeout 30
Setting Transmission Retry Count for the RADIUS Server
By default, a switch retries transmission to a RADIUS server only once before reverting to local
authentication. You can increase this number up to a maximum of five retries per server.To specify the
number of times that RADIUS servers should try to authenticate a user, follow these steps:
Command
Step 1
switch# config t
Step 2
switch(config)# radius-server retransmit 3
switch(config)# no radius-server
retransmit
OL-18084-01, Cisco MDS NX-OS Release 4.x
Purpose
Configures a preshared key (AnyWord) to
authenticate communication between the RADIUS
client and server. The default is clear text.
Configures a preshared key (AnyWord) specified in
clear text (indicated by 0) to authenticate
communication between the RADIUS client and
server.
Configures a preshared key (specified in encrypted
text) specified in encrypted text (indicated by 7) to
authenticate communication between the RADIUS
client and server.
Purpose
Enters configuration mode.
Configures the global timeout period in seconds for the switch
to wait for a response from all TACACS+ servers before the
switch declares a timeout failure. The time ranges from 1 to
1440 seconds.
Reverts the transmission time to the default value (1 second).
Purpose
Enters configuration mode.
Configures the number of times (3) the switch tries
to connect to a RADIUS server(s) before reverting
to local authentication.
Reverts to the default retry count (1).
Cisco MDS 9000 Family CLI Configuration Guide
Configuring RADIUS
34-11