Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Get Direct Link
- Report Inappropriate Content
‎10-20-2021 03:44 PM
It appears that, when configuring a RADIUS server, you can only select one of the options in the "used-by" portion of the command. This seems like an odd limitation. Am I missing something? Is it possible to use the same server for CLI & Web access authentication? It looks like if you try to add one it simply overwrites the other. I don't see the purpose of needing a separate server for each of those.
Solved! Go to Solution.
1 ACCEPTED SOLUTION
Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Get Direct Link
- Report Inappropriate Content
‎10-21-2021 08:36 AM
Ok, I got it to work by adding "used-by cli" and then entering again for "used-by web".
radius server host <SERVER1-IP> key <KEY> used-by cli
radius server host <SERVER1-IP> key <KEY> used-by web
radius server host <SERVER2-IP> key <KEY> used-by cli
radius server host <SERVER2-IP> key <KEY> used-by web
radius enable
radius server host <SERVER1-IP> key <KEY> used-by cli
radius server host <SERVER1-IP> key <KEY> used-by web
radius server host <SERVER2-IP> key <KEY> used-by cli
radius server host <SERVER2-IP> key <KEY> used-by web
radius enable
2 REPLIES 2
Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Get Direct Link
- Report Inappropriate Content
‎10-21-2021 08:36 AM
Ok, I got it to work by adding "used-by cli" and then entering again for "used-by web".
radius server host <SERVER1-IP> key <KEY> used-by cli
radius server host <SERVER1-IP> key <KEY> used-by web
radius server host <SERVER2-IP> key <KEY> used-by cli
radius server host <SERVER2-IP> key <KEY> used-by web
radius enable
radius server host <SERVER1-IP> key <KEY> used-by cli
radius server host <SERVER1-IP> key <KEY> used-by web
radius server host <SERVER2-IP> key <KEY> used-by cli
radius server host <SERVER2-IP> key <KEY> used-by web
radius enable
Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Get Direct Link
- Report Inappropriate Content
‎10-21-2021 03:17 AM
You have to create separate entries. In the long run it is cleaner, as you could end up with many used-by, not just cli and web, but eapol, ept, snmp..
