<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Radius Authenticate just Management or Network Access, on SecureStack in FAQs</title>
    <link>https://community.extremenetworks.com/t5/faqs/radius-authenticate-just-management-or-network-access-on/m-p/47168#M442</link>
    <description>Article ID: 5677&lt;BR /&gt;
&lt;BR /&gt;
&lt;B&gt;Products&lt;/B&gt;&lt;BR /&gt;
SecureStack C3&lt;BR /&gt;
SecureStack C2&lt;BR /&gt;
Firmware 3.01.94 and lower&lt;BR /&gt;
SecureStack B3&lt;BR /&gt;
SecureStack B2&lt;BR /&gt;
Firmware 1.01.45 and lower&lt;BR /&gt;
SecureStack A2&lt;BR /&gt;
Firmware 1.00.27 and lower &lt;BR /&gt;
&lt;BR /&gt;
&lt;B&gt;Protocols/Features&lt;/B&gt;&lt;BR /&gt;
Radius&lt;BR /&gt;
UPN &lt;BR /&gt;
&lt;BR /&gt;
&lt;B&gt;Goals&lt;/B&gt;&lt;BR /&gt;
Radius authenticate just device management access&lt;BR /&gt;
Radius authenticate just network access&lt;BR /&gt;
Authenticate to a RADIUS Server&lt;BR /&gt;
Sample configuration &lt;BR /&gt;
&lt;BR /&gt;
&lt;B&gt;Cause&lt;/B&gt;&lt;BR /&gt;
In order to permit Radius Authentication to regulate &lt;I&gt;just&lt;/I&gt; device Management access or &lt;I&gt;just&lt;/I&gt; user Network access, two elements must be configured: &lt;BR /&gt;
&lt;BR /&gt;
&lt;UL&gt; 
&lt;LI&gt;A 'management' vs 'network' selection on the Radius server 
&lt;/LI&gt;&lt;LI&gt;A matching 'management' vs 'network' selection on the managed device&lt;/LI&gt;&lt;/UL&gt;
With earlier firmware, SecureStacks can either Radius-authenticate &lt;I&gt;both&lt;/I&gt; management and network access, or neither. &lt;BR /&gt;
&lt;BR /&gt;
&lt;B&gt;Solution&lt;/B&gt;&lt;BR /&gt;
For the C2, upgrade to firmware 3.02.30 or higher. &lt;BR /&gt;
For the B2, upgrade to firmware 2.00.16 or higher. &lt;BR /&gt;
For the A2, upgrade to firmware 1.01.20 or higher. &lt;BR /&gt;
&lt;BR /&gt;
With these firmware versions, the DFE-like 'set radius realm' command is supported.&lt;BR /&gt;
C2(rw)-&amp;gt;set radius realm ?&lt;BR /&gt;
 &lt;BR /&gt;
 management-access        Sets Access type to management-access&lt;BR /&gt;
 network-access           Sets Access type to network-access&lt;BR /&gt;
 any                      Sets Access type to any-access&lt;BR /&gt;
 &lt;BR /&gt;
 C2(rw)-&amp;gt;&lt;BR /&gt;
Here is a sample partial configuration which authenticates against one server for network users and a different server for management access.&lt;BR /&gt;
 set radius enable&lt;BR /&gt;
 set radius server 1 1.2.3.4 1812 myfirstsecret realm network-access&lt;BR /&gt;
 set radius server 2 1.2.3.5 1812 myothersecret realm management-access</description>
    <pubDate>Wed, 06 Nov 2013 03:06:00 GMT</pubDate>
    <dc:creator>FAQ_User</dc:creator>
    <dc:date>2013-11-06T03:06:00Z</dc:date>
    <item>
      <title>Radius Authenticate just Management or Network Access, on SecureStack</title>
      <link>https://community.extremenetworks.com/t5/faqs/radius-authenticate-just-management-or-network-access-on/m-p/47168#M442</link>
      <description>Article ID: 5677&lt;BR /&gt;
&lt;BR /&gt;
&lt;B&gt;Products&lt;/B&gt;&lt;BR /&gt;
SecureStack C3&lt;BR /&gt;
SecureStack C2&lt;BR /&gt;
Firmware 3.01.94 and lower&lt;BR /&gt;
SecureStack B3&lt;BR /&gt;
SecureStack B2&lt;BR /&gt;
Firmware 1.01.45 and lower&lt;BR /&gt;
SecureStack A2&lt;BR /&gt;
Firmware 1.00.27 and lower &lt;BR /&gt;
&lt;BR /&gt;
&lt;B&gt;Protocols/Features&lt;/B&gt;&lt;BR /&gt;
Radius&lt;BR /&gt;
UPN &lt;BR /&gt;
&lt;BR /&gt;
&lt;B&gt;Goals&lt;/B&gt;&lt;BR /&gt;
Radius authenticate just device management access&lt;BR /&gt;
Radius authenticate just network access&lt;BR /&gt;
Authenticate to a RADIUS Server&lt;BR /&gt;
Sample configuration &lt;BR /&gt;
&lt;BR /&gt;
&lt;B&gt;Cause&lt;/B&gt;&lt;BR /&gt;
In order to permit Radius Authentication to regulate &lt;I&gt;just&lt;/I&gt; device Management access or &lt;I&gt;just&lt;/I&gt; user Network access, two elements must be configured: &lt;BR /&gt;
&lt;BR /&gt;
&lt;UL&gt; 
&lt;LI&gt;A 'management' vs 'network' selection on the Radius server 
&lt;/LI&gt;&lt;LI&gt;A matching 'management' vs 'network' selection on the managed device&lt;/LI&gt;&lt;/UL&gt;
With earlier firmware, SecureStacks can either Radius-authenticate &lt;I&gt;both&lt;/I&gt; management and network access, or neither. &lt;BR /&gt;
&lt;BR /&gt;
&lt;B&gt;Solution&lt;/B&gt;&lt;BR /&gt;
For the C2, upgrade to firmware 3.02.30 or higher. &lt;BR /&gt;
For the B2, upgrade to firmware 2.00.16 or higher. &lt;BR /&gt;
For the A2, upgrade to firmware 1.01.20 or higher. &lt;BR /&gt;
&lt;BR /&gt;
With these firmware versions, the DFE-like 'set radius realm' command is supported.&lt;BR /&gt;
C2(rw)-&amp;gt;set radius realm ?&lt;BR /&gt;
 &lt;BR /&gt;
 management-access        Sets Access type to management-access&lt;BR /&gt;
 network-access           Sets Access type to network-access&lt;BR /&gt;
 any                      Sets Access type to any-access&lt;BR /&gt;
 &lt;BR /&gt;
 C2(rw)-&amp;gt;&lt;BR /&gt;
Here is a sample partial configuration which authenticates against one server for network users and a different server for management access.&lt;BR /&gt;
 set radius enable&lt;BR /&gt;
 set radius server 1 1.2.3.4 1812 myfirstsecret realm network-access&lt;BR /&gt;
 set radius server 2 1.2.3.5 1812 myothersecret realm management-access</description>
      <pubDate>Wed, 06 Nov 2013 03:06:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/faqs/radius-authenticate-just-management-or-network-access-on/m-p/47168#M442</guid>
      <dc:creator>FAQ_User</dc:creator>
      <dc:date>2013-11-06T03:06:00Z</dc:date>
    </item>
  </channel>
</rss>

