Description:

This article describes how access management can be configured on a switch of the GS-23xx series via RADIUS (802.1x). Thus it is possible to administer login credentials for users in a central place.


Requirements:


Procedure:

1) Configuration of the RADIUS authentication on the switch:

1.1) Open the switch configuration in a browser, go to the menu Security → AAA → Configuration, enter the RADIUS server information under RADIUS Authentication Server Configuration and click Apply

 

1.2) Go to the menu Security → Access Management → Auth Method, set the Authentication Method to RADIUS for the necessary access options and click Apply.

Activating the option Fallback is recommended, as the authentication at the switch with the local logiin credentials is possible when the RADIUS server isn't reachable.

1.3) Go to the menu Maintenance → Save/Restore → Save Start and click Save to save the configuration as Start Configuration.

The Start Configuration is saved boot persistent in the device and is therefore still available after a reboot or a power outage.

1.4) The configuration of the switch is now complete.



2) Configuration of the RADIUS server on a LANCOM router or access point:

If a separate RADIUS server is used, the Privilege Level has to be committed via a Cisco AV Pair entry with the string shell:priv-lvl=x (x stands for a value between 1-15, whereas the value 15 has the highest priority).

The protocol PAP has to be used for authenticating the switch with the RADIUS server, as the GS-23xx series only supports this protocol.

2.1) Open the configuration of the device in LANconfig, go to the menu RADIUS → Server and activate the checkbox RADIUS authentication active.

2.2) Go to the menu RADIUS services ports.

2.3) Make sure, that the Authentication port 1812 is used.

2.4 ) Go to the menu IPv4 clients.

2.5) Create a new entry and change the following parameters:

2.6) Go to the menu User table.

2.7) Create a new entry and change the following parameters:

The Shell privilege level can be set between 1 - 15, whereas the value 15 has the highest priority.

It is possible to assign different Privilege levels to the function groups in the menu System → Account → Privilege-Level. Thus it is possible to assign different rights to users.

2.8) The configuration of the RADIUS server is now complete. Write the configuration back into the router.