How to allow RADIUS admin to login the switch? (by TekRADIUS)
Zyxel_Melen
Posts: 2,649 Zyxel Employee
Scenario
Some users might prefer to use RADIUS server to manage the access control for the network devices, Zyxel switch provides users to use RADIUS server to authenticate the switch login. This FAQ will use GS2220 and TekRADIUS for example.
Topology
Configuration
V4.70 version firmware:
- Navigate to Advanced Application > AAA > RADIUS Server Setup to configure the authentication Server.
- Navigate to Advanced Application > AAA > AAA Setup to configure “Authentication” and “Authorization.”
Authentication > Login should set radius in method 1, and method 2 can be “-” or “local.”
Authorization > Exec should be active and set method as radius.
V4.80 version firmware:
- Navigate to Security > AAA > RADIUS Server Setup to configure the authentication Server.
- Navigate to Advanced Application > AAA > AAA Setup to configure “Authentication” and “Authorization.”
Authentication > Login should set radius in method 1, and method 2 can be “-” or “local.”
Authorization > Exec should be active and set method as radius. V4.80 firmware supports server key encryption; the shared secret will be stored on the Switch in an encrypted format and displayed as ‘*’ in the SECURITY > AAA > RADIUS Server Setup and SECURITY > AAA > TACACS+ Server Setup screens. Users can consider enabling it to prevent shared secrets from being exposed.
TekRADIUS part:
Setup TekRADIUS:
- Set RADIUS client: 192.168.1.1 with shared key 12345678.
- Create a new account “zyuser” and its password “1234”.
- Add attribute “service-type” with type “Success-Reply“ and value “login” to zyuser.
- Create a new attribute string: “Zyxel-Privilege-AVPair” whose attribute ID is “3”. The vendor ID of Zyxel is “890”.
- Add the attribute string “Zyxel-Privilege-AVPair” with type “Success-Reply” and value “shell:priv-lvl=14” to zyuser.
Verify
- Client can access the telnet session on the Switch:
- Client accesses the Switch via console.
- Capture RADIUS packets on RADIUS Server side.
- RADIUS request from Client
- RADIUS accepts from Server
- RADIUS request from Client
Zyxel Melen
0
Categories
- All Categories
- 415 Beta Program
- 2.4K Nebula
- 151 Nebula Ideas
- 98 Nebula Status and Incidents
- 5.7K Security
- 277 USG FLEX H Series
- 277 Security Ideas
- 1.4K Switch
- 74 Switch Ideas
- 1.1K Wireless
- 42 Wireless Ideas
- 6.4K Consumer Product
- 250 Service & License
- 395 News and Release
- 85 Security Advisories
- 29 Education Center
- 10 [Campaign] Zyxel Network Detective
- 3.6K FAQ
- 34 Documents
- 34 Nebula Monthly Express
- 85 About Community
- 74 Security Highlight