cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1661
Views
0
Helpful
3
Replies

Nexus_RAdius config

incognito
Level 1
Level 1

hi

Can someone check it? Is it right config for radius on nexus switch?

 

radius-server host 10.100.0.5 key 7 "******" authentication accounting
aaa group server radius RadServer

aaa authentication login default group RadServer local
aaa accounting default group RadServer
aaa authentication login error-enable

 


server 10.100.0.5
use-vrf vsan

3 Replies 3

balaji.bandi
Hall of Fame
Hall of Fame

here is example working config :

aaa group server radius RADIUS-BB
server x.x.x.x
server y.y.y.y
use-vrf management ( generally this go via Management, you can use any VRF which can reach to Radius servers)

 

radius-server host x.x.x.x key 7 "mykey" authentication accounting
radius-server host y.y.y.y key 7 "mykey2" authentication accounting <- if you have 2 Radius
radius-server directed-request

aaa authentication login console local <- in case if you lock out with Radius)
aaa authentication login default group RADIUS-BB Local


Do not write the config untill all tested and working

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

1) Why did you use 2 server command? I have only one radius server (10.100.0.5). As i understand i can use only one server x.x.x.x command, right?

server x.x.x.x
server y.y.y.y

 

2) use-vrf management ( generally this go via Management, you can use any VRF which can reach to Radius servers).

In my case I have to use vrf vsan 

 

3) For what do we use this command?
radius-server directed-request 

4) what does Local mean at the end of this command?

aaa authentication login default group RADIUS-BB Local

 

Can you check the config now?

radius-server host 10.100.0.5 key 7 "******" authentication accounting
aaa group server radius RadServer

server 10.100.0.5
use-vrf vsan

aaa authentication login default group RadServer local
aaa accounting default group RadServer
aaa authentication login error-enable

aaa authentication login console local 


but radius sever is not working. I cant remotely connect to the nexus switch with radius(active directory) user credentials. Radius on windows server is configured correct. the problem is on the nexus side

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card