Configuring RADIUS Authentication and Authorization

You can configure RADIUS Remote Authentication Dial-In User Service is a networking protocol that provides centralized authentication, authorization, and accounting management for users who connect and use a network service  servers to authenticate HPE Aruba Networking Central On-Premises users. For RADIUS capability, you must configure the IP/hostname of the RADIUS server, the server shared secret, and the authentication protocol.

To configure RADIUS servers to authenticate users, complete the following steps:

  1. In the HPE GreenLake account home page, click Manage.

    The Manage Account page is displayed.

  2. Click the Authentication card.

    The Authentication tab is displayed by default.

  3. Click Edit.

    The Authentication Method drop-down list is displayed.

  4. Select RADIUS from the drop-down list.
  5. Click Set up Radius Server at the bottom of the page.

    The Add Primary Server pop-up window is displayed.

    At this point, you cannot save changes to the authentication method unless you configure a RADIUS server.

  6. Configure the following parameters:

  7. Click Add.

    The Authentication page is displayed again.

  8. (Optional) Click Set Up Radius Server once again to configure the parameters for secondary server.

    • The authentication protocol that you selected for the primary server will be auto-populated and set as the default for the secondary server.

    • If authentication fails with the primary server, the request is made to the secondary server for authentication. If both fail, the request authenticates against the default Local User Database.
    • All the node IP addresses need to be configured as RADIUS clients on the RADIUS server.
  9. Configure the secondary server parameters as described in step .

  10. Click Add.

    The Authentication page is displayed once again.

  11. Click Save Changes.

    The Change Authentication Method? confirmation box is displayed.

  12. Click Confirm Change.

    The authentication method is changed from the local user database to RADIUS server.