Jump to content
Toggle menu
  • 51 articles
  • 24 files
  • 4 users
  • 750 edits
Tech-Wiki
Toggle preferences menu
Toggle personal menu
Not logged in
Your IP address will be publicly visible if you make any edits.

Configure RADIUS AAA authentication on Cisco IOS XE

From Tech-Wiki


Configure central administrative authentication with RADIUS and Cisco IOS XE AAA, with a controlled local fallback.

ⓘ
Validation status
Reviewed against current Cisco IOS XE RADIUS configuration documentation and the Cisco IOS XE Software Hardening Guide on 27 September 2026.
!
Avoid management lockout
AAA changes can remove administrative access if the RADIUS servers, routing, source interface, shared secret or method list are incorrect. Maintain an approved recovery path and test RADIUS and fallback authentication before ending the original administrative session.

Define named RADIUS servers

Current IOS XE supports named RADIUS server objects. The older radius-server host syntax used by many legacy configurations has been deprecated on some IOS XE releases in favour of radius server name.

>_Define two RADIUS servers
radius server RADIUS-A
 address ipv4 192.0.2.10 auth-port 1812 acct-port 1813
 key RADIUS_SHARED_SECRET
!
radius server RADIUS-B
 address ipv4 192.0.2.11 auth-port 1812 acct-port 1813
 key RADIUS_SHARED_SECRET

Replace the documentation addresses and placeholder shared secret with approved values.

!
Do not reuse Type 7 values
The legacy Tech-Wiki article contained Type 7 encoded RADIUS keys. Cisco's current hardening guidance states that Type 7 is not secure storage. Use the strongest supported organisation-approved reversible secret protection for RADIUS keys, such as Type 6 on platforms where it is supported and configured.

Create the RADIUS server group

>_Create a named server group
aaa group server radius RADIUS_SERVERS
 server name RADIUS-A
 server name RADIUS-B

If a dedicated source interface is required, configure it according to the target platform and management-routing design.

>_Example RADIUS source interface
ip radius source-interface Loopback0

Configure AAA method lists

Enable AAA and create a login method list that uses the RADIUS group first and a local account as fallback.

>_AAA authentication and EXEC authorisation
aaa new-model
aaa authentication login VTY_AUTH group RADIUS_SERVERS local
aaa authorization exec default group RADIUS_SERVERS local

Apply the named login method list to the VTY lines and allow SSH only:

>_Apply AAA to VTY access
line vty 0 4
 login authentication VTY_AUTH
 transport input ssh

Apply the approved policy to all required VTY lines on the target device.

Protect fallback accounts

A local fallback account should exist before central AAA is enforced and should use the strongest local secret format supported by the target IOS XE release.

>_Example local fallback account
username netadmin privilege 15 algorithm-type scrypt secret REPLACE_WITH_STRONG_SECRET

Keep fallback credentials controlled and tested according to the organisation's privileged-access process.

Verify

Review RADIUS server state and test both the central authentication path and the planned fallback path before closing the existing session.

>_Useful verification commands
show aaa servers
show running-config | section radius

Official references

See also