926 | Security
www.dell.com | support.dell.com
RADIUS Authentication and Authorization
FTOS supports RADIUS for user authentication (text password) at login and can be specified as one of the
login authentication methods in the
aaa authentication login command.
When configuring AAA authorization, you can configure to limit the attributes of services available to a
user. When authorization is enabled, the network access server uses configuration information from the
user profile to issue the user's session. The user’s access is limited based on the configuration attributes.
FTOS supports the following RADIUS attributes:
Code Attribute
1 RADIUS_USER_NAME
2 RADIUS_USER_PASSWORD
4 RADIUS_NAS_IP_ADDRESS
5 RADIUS_NAS_PORT
11 RADIUS_FILTER_ID (for ACL)
26 RADIUS_VENDOR_SPECIFIC (privilege level/auto-command)
28 RADIUS_IDLE_TIMEOUT
61 RADIUS_NAS_PORT_TYPE
95 NAS_IPv6_ADDRESS
802.1x supported:
1 RADIUS_USER_NAME
4 RADIUS_NAS_IP_ADDRESS
5 RADIUS_NAS_PORT
24 RADIUS_STATE
30 RADIUS_CALLING_STATION_ID
61 RADIUS_NAS_PORT_TYPE
64 RADIUS_TUNNEL_TYPE
65 RADIUS_TUNNEL_MEDIUM_TYPE