RADIUS server group configuration options
Navigation path
. Choose and edit a configured RADIUS Server Group object or add a new one.
Fields
-
Name and Description—Enter a name and optionally, a description to identify this RADIUS Server Group object.
-
Group Accounting Mode—Defines how accounting messages are sent to the RADIUS servers. Choose one of these:
-
Single—Sends accounting messages to a single server (default).
-
Multiple—Sends accounting messages to all servers in the group simultaneously.
-
-
Retry Interval—Sets the interval (1–10 seconds) between attempts to contact RADIUS servers.
-
Realms(Optional)—Specify the Active Directory (AD) realm associated with this RADIUS server group. The selected realm is referenced in identity policies to determine VPN authentication identity sources for relevant traffic flows. This realm effectively provides a bridge from the identity policy to this RADIUS server group. If no realm is associated with this RADIUS server group, the RADIUS server group cannot be reached to determine the VPN authentication identity source for a traffic flow in an identity policy.
NoteThis field is mandatory if you use remote access VPN with User Identity and RADIUS as the identity source.
-
Enable authorize only—If the group is used only for authorization or accounting (not authentication), enable authorize-only mode. This mode omits the RADIUS server password from Access-Request messages; the configured password for individual RADIUS servers is ignored.
-
Enable interim account update and Interval—Enables the generation of interim accounting update messages to notify the RADIUS server of newly assigned IP addresses. The Interval option sets the period (1 to 120 hours; default is 24 hours) between updates.
-
Enable Dynamic Authorization and Port— Enables the RADIUS dynamic authorization or change of authorization (CoA) services for this RADIUS server group. Specify the listening port for RADIUS CoA requests in the Port field. The valid range is 1024 to 65535 and the default value is 1700. Once defined, the corresponding RADIUS server group will be registered for CoA notification and it listens to the port for the CoA policy updates from the Cisco Identity Services Engine (ISE).
-
Merge Downloadable ACL with Cisco AV Pair ACL—Enables merging a downloadable access control list (dACL) with a Cisco attribute-value (AV) pair ACL.
A downloadable ACL defines and updates access control lists in Cisco ISE. Administrators can then download the updated ACLs to all applicable controllers. For more information about using dACLs in Cisco ISE, see the chapter on Segmentation, section on authorization policies, in the Cisco ISE Administrator Guide.
A Cisco AV pair ACL can be utilized to define specific authentication, authorization, and accounting elements for each individual session. For more information about using dACLs in Cisco ISE, see the chapter on Segmentation, section on authorization profile settings, in the Cisco ISE Administrator Guide.
If you select Merge Downloadable ACL with Cisco AV Pair ACL, you can choose the following options:
-
After Cisco AV Pair ACL—Place downloadable ACL entries after AV pair entries.
-
Before Cisco AV Pair ACL—Place downloadable ACL entries before AV pair entries.
-
-
RADIUS Servers—For server-specific configuration options, see Configure RADIUS server options.