Configure RADIUS AAA authentication on Cisco IOS XE
More actions
Configure central administrative authentication with RADIUS and Cisco IOS XE AAA, with a controlled local fallback.
Define named RADIUS servers
Current IOS XE supports named RADIUS server objects. The older radius-server host syntax used by many legacy configurations has been deprecated on some IOS XE releases in favour of radius server name.
radius server RADIUS-A address ipv4 192.0.2.10 auth-port 1812 acct-port 1813 key RADIUS_SHARED_SECRET ! radius server RADIUS-B address ipv4 192.0.2.11 auth-port 1812 acct-port 1813 key RADIUS_SHARED_SECRET
Replace the documentation addresses and placeholder shared secret with approved values.
Create the RADIUS server group
aaa group server radius RADIUS_SERVERS server name RADIUS-A server name RADIUS-B
If a dedicated source interface is required, configure it according to the target platform and management-routing design.
ip radius source-interface Loopback0
Configure AAA method lists
Enable AAA and create a login method list that uses the RADIUS group first and a local account as fallback.
aaa new-model aaa authentication login VTY_AUTH group RADIUS_SERVERS local aaa authorization exec default group RADIUS_SERVERS local
Apply the named login method list to the VTY lines and allow SSH only:
line vty 0 4 login authentication VTY_AUTH transport input ssh
Apply the approved policy to all required VTY lines on the target device.
Protect fallback accounts
A local fallback account should exist before central AAA is enforced and should use the strongest local secret format supported by the target IOS XE release.
username netadmin privilege 15 algorithm-type scrypt secret REPLACE_WITH_STRONG_SECRET
Keep fallback credentials controlled and tested according to the organisation's privileged-access process.
Verify
Review RADIUS server state and test both the central authentication path and the planned fallback path before closing the existing session.
show aaa servers show running-config | section radius