This lesson describes how to configure radius authentication for management access on EAGLE20/One
Configure Radius Server
data:image/s3,"s3://crabby-images/d6a89/d6a8997a7fbbbec96c14164f5922883f7a679702" alt=""
In the webinterface navigate to Security -- External Authentication -- RADIUS Server
and specify the IP address, port and secret of the radius server
CLI command:
!*(Hirschmann Eagle) (config)#radius server 1 modify ip-address <ip address> port 1812 secret <shared secret>
!*(Hirschmann Eagle) (config)#radius server 1 status enable
Configure Authentication list
data:image/s3,"s3://crabby-images/43483/43483017d4dc2ee67ae3cbc83c67b84a483f3536" alt=""
Navigate to Security -- External Authentication -- Authentication List
1. Create a new entry 'radiuslist' with first method 'radius'
2. Specify 'radiuslist' as authentication list for unknown system login users
CLI commands:
!*(Hirschmann Eagle) (config)#authentication login radiuslist add
!*(Hirschmann Eagle) (config)#authentication login radiuslist set radius
!*(Hirschmann Eagle) (config)#authentication login radiuslist enable
!*(Hirschmann Eagle) (config)#authentication login radiuslist default
SNMP over HTTPS
data:image/s3,"s3://crabby-images/2c7ee/2c7eeea6057d1d2a8a521011855f51143f965c88" alt=""
Enable SNMP over HTTPS otherwise radius authentication does not work for webinterface login.
Radius Server Configuration
Service-Types
e.g. freeradius server:
Service-Type = NAS-Prompt-User - Management Read-Only User
Service-Type = Administrative-User - Management Read-Write User
There is no access without valid service-type