BelAir20E User Guide
Wi-Fi AP Security
April 2, 2012
Confidential
Document Number BDTM02201-A01 Standard
Managing RADIUS
Servers
/protocol/radius/show servers
/protocol/radius/set server <server_idx> <server_ip_address>
<shared secret> [authport <server_port>]
[acctport <radius_acc_port>]
[interface <NAS IP address>] [timeout <seconds>]
[
reauthtime <seconds>]
/protocol/radius/del server <server_idx>
These commands let you manage the RADIUS server list used for
authenticating wireless clients. The list can contain up to 16 RADIUS servers.
After the list is configured, you can then assign which AP SSID uses which
server on the list. See
“Assigning SSIDs to RADIUS Servers” on page 105
. By
default, if a RADIUS server is unavailable, then the SSID uses the next RADIUS
server in the list. You cannot delete a server if it is being used by an SSID.
The
server_ip address
parameter specifies the IP address of the RADIUS
server.
The
shared secret
parameter specifies the password for access to the RADIUS
server.
The
server_port
parameter ranges from 0 to 65535. It specifies the UDP port
number of the RADIUS server. The default is 1812.
The
radius_acc_port
parameter ranges from 0 to 65535. It specifies the UDP
port number for RADIUS accounting data. The default value is 1813.
The
NAS IP address
parameter specifies the Network Access Server (NAS) IP
address for the BelAir20E RADIUS client. It is used when the unit is configured
with multiple IP interfaces and matches the interface used to communicate with
the given RADIUS server. The default value is the IP address of the unit’s
management interface, which is usually the system’s default IP address.
Note: The
NAS IP address
parameter is entered statically with this command.
If the VLAN IP addresses are determined dynamically with a DHCP
RA_CONNECT_INFO
77 Always
CONNECT 11Mbps 802.11b
RA_EAP_MESSAGE
79 EAP packet
RA_MESSAGE_AUTHENTICATOR
80 Authentication string from RADIUS server
RA_INTERIM_INTERVAL
85 Not used
Table 10: RADIUS Attributes (Continued)
Name
ID Description