Netgear GS724Tv4 Software Administration Manual - Page 180

RADIUS Server Configuration, To add a primary RADIUS server with a shared secret, Security

Page 180 highlights

GS716Tv3, GS724Tv4, and GS748Tv5 Smart Switches RADIUS Server Configuration Use the RADIUS Server Configuration screen to view and configure various settings for the current RADIUS server configured on the system.  To add a primary RADIUS server with a shared secret: 1. Select Security > Management Security > RADIUS > Server Configuration. 2. In the Server Address field, specify the IP address of the RADIUS server to add. 3. In the Authentication Port field, specify the UDP port number the server uses to verify the RADIUS server authentication. The valid range is 1-65535. The default value is 1812. 4. From the Secret Configured list, select Yes. You must select Yes before you can configure the RADIUS secret. After you add the RADIUS server, this field indicates whether the shared secret for this server has been configured. 5. In the Secret field, type the shared secret text string used for authenticating and encrypting all RADIUS communications between the switch and the RADIUS server. This secret must match the RADIUS encryption. 6. From the Active list, select Primary. 7. From the Message Authenticator list, enable or disable the message authenticator attribute for the selected server. The message authenticator adds protection to RADIUS messages by using an MD5 hash to encrypt each message. The shared secret is used as the key, and if the message fails to be verified by the RADIUS server, it is discarded. 8. Click the Add button. The following table describes the RADIUS server statistics available on the screen. Table 58. RADIUS server statistics Field Server Address Round Trip Time Access Requests Access Retransmissions Access Accepts Access Rejects Description This displays all configured RADIUS servers. The time interval, in hundredths of a second, between the most recent Access-Reply/Access-Challenge and the Access-Request that matched it from this RADIUS authentication server. The number of RADIUS Access-Request packets sent to this server. This number does not include retransmissions. The number of RADIUS Access-Request packets retransmitted to this server. The number of RADIUS Access-Accept packets, including both valid and invalid packets, that were received from this server. The number of RADIUS Access-Reject packets, including both valid and invalid packets, that were received from this server. Managing Device Security 180

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290

Managing Device Security
180
GS716Tv3, GS724Tv4, and GS748Tv5 Smart Switches
RADIUS Server Configuration
Use the RADIUS Server Configuration screen to view and configure various settings for the
current RADIUS server configured on the system.
To add a primary RADIUS server with a shared secret:
1.
Select
Security
>
Management Security
>
RADIUS
>
Server Configuration
.
2.
In the Server Address field, specify the IP address of the RADIUS server to add.
3.
In the Authentication Port field, specify the UDP port number the server uses to verify the
RADIUS server authentication. The valid range is 1–65535. The default value is 1812.
4.
From the Secret Configured list, select
Yes
.
You must select
Yes
before you can configure the RADIUS secret. After you add the
RADIUS server, this field indicates whether the shared secret for this server has been
configured.
5.
In the Secret field, type the shared secret text string used for authenticating and encrypting
all RADIUS communications between the switch and the RADIUS server.
This secret must match the RADIUS encryption.
6.
From the Active list, select
Primary
.
7.
From the Message Authenticator list, enable or disable the message authenticator attribute
for the selected server.
The message authenticator adds protection to RADIUS messages by using an MD5 hash
to encrypt each message. The shared secret is used as the key, and if the message fails
to be verified by the RADIUS server, it is discarded.
8.
Click the
Add
button.
The following table describes the RADIUS server statistics available on the screen.
Table 58.
RADIUS server statistics
Field
Description
Server Address
This displays all configured RADIUS servers.
Round Trip Time
The time interval, in hundredths of a second, between the most recent
Access-Reply/Access-Challenge and the Access-Request that matched
it from this RADIUS authentication server.
Access Requests
The number of RADIUS Access-Request packets sent to this server.
This number does not include retransmissions.
Access Retransmissions
The number of RADIUS Access-Request packets retransmitted to this
server.
Access Accepts
The number of RADIUS Access-Accept packets, including both valid
and invalid packets, that were received from this server.
Access Rejects
The number of RADIUS Access-Reject packets, including both valid
and invalid packets, that were received from this server.