Purpose
Command or Action
switch(config)#
show radius pending
Applies the RADIUS configuration changes in the
temporary database to the running configuration.
(Optional)
radius commit
Example:
Step 4
switch(config)#
radius commit
Exits configuration mode.
exit
Example:
Step 5
switch(config)#
exit
switch#
Displays the RADIUS server configuration.
(Optional)
show radius-server
Example:
Step 6
switch#
show radius-server
Copies the running configuration to the startup
configuration.
(Optional)
copy running-config startup-config
Example:
Step 7
switch#
copy running-config startup-config
Related Topics
Configuring RADIUS Server Groups
, on page 48
Configuring One-Time Passwords
One-time password (OTP) support is available for Cisco NX-OS devices through the use of RSA SecurID
token servers. With this feature, users authenticate to a Cisco NX-OS device by entering both a personal
identification number (or one-time password) and the token code being displayed at that moment on their
RSA SecurID token.
The token code used for logging into the Cisco NX-OS device changes every 60 seconds. To prevent problems
with device discovery, we recommend using different usernames that are present on the Cisco Secure ACS
internal database.
Note
Before you begin
On the Cisco NX-OS device, configure a RADIUS server host and remote default login authentication.
Ensure that the following are installed:
• Cisco Secure Access Control Server (ACS) version 4.2
• RSA Authentication Manager version 7.1 (the RSA SecurID token server)
• RSA ACE Agent/Client
No configuration (other than a RADIUS server host and remote authentication) is required on the Cisco
NX-OS device to support one-time passwords. However, you must configure the Cisco Secure ACS as follows:
Cisco Nexus 9000 Series NX-OS Security Configuration Guide, Release 9.x
61
Configuring RADIUS
Configuring One-Time Passwords