Legal Disclaimer: The resource assets in this website may include abbreviated and/or legacy terminology for HPE Aruba Networking products. See www.arubanetworks.com for current and complete HPE Aruba Networking product lines and names.
Configuring RADIUS Authentication and Authorization
You can configure RADIUS Remote Authentication Dial-In User Service is a networking protocol that provides centralized authentication, authorization, and accounting management for users who connect and use a network service servers to authenticate HPE Aruba Networking Central On-Premises users. For RADIUS capability, you must configure the IP/hostname of the RADIUS server, the server shared secret, and the authentication protocol.
To configure RADIUS servers to authenticate users, complete the following steps:
- In the HPE GreenLake account home page, click .
The Manage Account page is displayed.
-
Click the Authentication card.
The Authentication tab is displayed by default.
-
Click Edit.
The Authentication Method drop-down list is displayed.
- Select RADIUS from the drop-down list.
-
Click Set up Radius Server at the bottom of the page.
The Add Primary Server pop-up window is displayed.
At this point, you cannot save changes to the authentication method unless you configure a RADIUS server.
-
Server Hostname or IP Address—Enter a specific hostname or IP address that points to the validating server.
-
Port—Enter the port number to be used.
-
Server Secret—Enter the shared secret used to access the primary RADIUS server.
-
Confirm Server Secret—Re-enter the shared secret for confirmation.
-
Authentication Protocol—Select one of the following supported authentication methods to apply to both primary and secondary servers:
-
Click Add.
The Authentication page is displayed again.
-
(Optional) Click Set Up Radius Server once again to configure the parameters for secondary server.
-
The authentication protocol that you selected for the primary server will be auto-populated and set as the default for the secondary server.
- If authentication fails with the primary server, the request is made to the secondary server for authentication. If both fail, the request authenticates against the default Local User Database.
- All the node IP addresses need to be configured as RADIUS clients on the RADIUS server.
-
-
Configure the secondary server parameters as described in step .
-
Click Add.
The Authentication page is displayed once again.
-
Click Save Changes.
The Change Authentication Method? confirmation box is displayed.
-
Click Confirm Change.
The authentication method is changed from the local user database to RADIUS server.
-
To know more about how to configure RADIUS service in HPE Aruba Networking ClearPass Policy Manager, see Configuring RADIUS Service in HPE Aruba Networking ClearPass Policy Manager
-
To know more about RADIUS server user roles RADIUS Server User Roles