Basic Configuration
58
EtherXtend User’s Guide
Note:
Follow the RADIUS server guidelines for RADIUS
configuration instructions. For example, when using the EtherXtend
with the FreeRadius server:
•
Create only one entry in the clients.conf file for each subnet or
individual EtherXtend. For individual EtherXtends, the IP in this
file must match the IP address of the outbound interface used by
the EtherXtend to connect to the RADIUS server.
•
The EtherXtend uses the value stored in the RADIUS
system.sysname file for the NAS-Identifier attribute.
•
The shared-secret in the EtherXtend radius-client profile, must
exactly match the shared-secret in the RADIUS client entry.
Configuring RADIUS support
The EtherXtend can be configured for local authentication, RADIUS
authentication, or RADIUS then local authentication. Multiple radius-client
profiles can be defined using the index and subindex numbers. This index
scheme can be used to create index numbers for groups of RADIUS servers.
When an index number is specified in the system profile, the EtherXtend
attempts authentication from each RADIUS server in that group in sequential
order of the subindex numbers.
To configure RADIUS support:
Note:
Before beginning this procedure, ensure that the EtherXtend
has IP connectivity to the RADIUS server.
1
Update the RADIUS server with settings for the Zhone prompts.
2
Create a radius-client profile on the EtherXtend with the desired index
number and RADIUS settings for server name, shared secret, number of
retries, and other parameters. The first number in the index is used to
group radius-client profiles so multiple profiles can be assigned to a
EtherXtend. The second number in the index specifies the order in which
radius-client profiles are referenced.
This example specifies the radius-client 1/1 with server name
radius1
and
a shared-secret of
secret
. The IP address is leased from a DHCP server so
a DNS resolver must be configured in the system to resolve the server
name and IP address.If a DNS resolver is not available, specify the IP
address of the The index 1/1 specifies that this profile is the first profile in
group 1.
zSH>
new radius-client 1/1
Please provide the following: [q]uit.
server-name: ----> {}: radius1.test.com
[DNS resolver must be configured in the system.]
udp-port: -------> {1812}:
shared-secret: --> {** password **}:
secret
retry-count: ----> {5}:
retry-interval: -> {1}:
Summary of Contents for EtherXtend 3300 Series
Page 8: ...Contents 6 EtherXtend User s Guide...
Page 18: ...Overview 16 EtherXtend User s Guide...
Page 70: ...Basic Configuration 68 EtherXtend User s Guide...
Page 132: ...Advanced Configuration 130 EtherXtend User s Guide...
Page 146: ...IP Service Level Agreement 144 EtherXtend User s Guide...
Page 150: ...Index 148 EtherXtend User s Guide...