Configuring RadSec Authentication and Authorization

You can configure RadSec RadSec is an authentication and authorization protocol for transporting RADIUS datagrams over TCP and TLS.  servers to authenticate HPE Aruba Networking Central On-Premises users. The RadSec protocol is used for safely transmitting the authentication and accounting data between the device and the RadSec server. For RadSec capability, you must configure the IP/hostname of the RadSec server, the server shared secret, and the authentication protocol.

To configure RadSec servers to authenticate users, complete the following steps:

  1. In the HPE GreenLake account home page, click Manage.

    The Manage Account page is displayed.

  2. Click the Authentication card.

    The Authentication tab is displayed by default.

  3. Click Edit.

    The Authentication Method drop-down list is displayed.

  4. Select RadSec from the drop-down list.
  5. Click Add RadSec Server at the bottom of the page.

    The Add Primary Server pop-up window is displayed.

  6. Configure the following parameters:

  7. Click Add.

    The Authentication page is displayed again.

  8. (Optional) Click Add RadSec Server once again to configure the parameters for secondary server.

    • The authentication protocol that you selected for the primary server will be auto-populated and set as the default for the secondary server.

    • If authentication fails with the primary server, the request is made to the secondary server for authentication. If both fail, the request authenticates against the default Local User Database.
  9. Configure the secondary server parameters as described in step 6.

  10. Click Add.

    The Authentication page is displayed once again.

  11. Click Save Changes.

    The Change Authentication Method? confirmation box is displayed.

  12. Click Confirm Change.

    The authentication method is changed from the local user database to RadSec server.