Configure RADIUS server options

Use this topic to configure a RADIUS server, including authentication, accounting, connectivity, and security settings.

Navigation path

Objects > AAA Server > RADIUS Server Group. Choose and edit a listed RADIUS Server Group object, or add a new one. In the RADIUS Server Group dialog, choose and edit a RADIUS Server or add a new server.

Fields

  • IP Address/Hostname—Specify the hostname or IP address (IPv4 or IPv6) of the RADIUS server that receives authentication requests. Only one server may be selected. To add servers, add more RADIUS Server entries to the RADIUS Server Group list.

  • RADIUS Server-Enabled Message Authenticator—Message authenticators safeguard server-to-client communication and are required for a secure connection between your RADIUS server and firewall devices. Disabling message authenticators may expose your firewalls to potential attacks.

    Your RADIUS server must support and be configured for Message-Authenticator. Requires Firewall Threat Defense Version 7.2.10+, 7.4.3+, or 7.6.1+. For the Firepower 4100/9300, this feature may require an FXOS upgrade; for minimum builds, see Cisco Secure Firewall Threat Defense Compatibility Guide.

  • Authentication Port—The port on which RADIUS authentication and authorization are performed. The default is 1812.

  • Key and Confirm Key—Enter the shared secret to encrypt data between the managed device (client) and the RADIUS server.

    The key is a case-sensitive, alphanumeric string of up to 127 characters. Special characters are permitted.

    Enter the same key in this field and on the RADIUS server. Enter the shared secret again in the Confirm field.

  • Accounting Port—Enter the port number for RADIUS accounting. The default port is 1813.

  • Timeout—Specify the session timeout for authentication.

    Set the timeout value to 60 seconds or more for RADIUS two-factor authentication. The default timeout value is 10 seconds.

  • Connect Using —Select the method to connect the device to a RADIUS server using either a route lookup or a specific interface.

    • Click the Routing radio button to use the routing table.

    • Click the Specific Interface radio button and choose a security zone/interface group or the Management interface (the default) from the drop-down list. If you want to use Management, you must choose it specifically; it is not available when using a route lookup. You cannot specify any other management-only interface as the RADIUS source.You can also choose a loopback interface group.

  • Redirect ACL—Select the redirect ACL from the list or add a new one.

    Use the ACL name from the device to control redirected traffic. The Redirect ACL name here must be the same as the redirect-ACL name in ISE server. When you configure the ACL object, ensure that you select Block action for ISE and DNS servers, and Allow action for the rest of the servers.