Legal Disclaimer: The resource assets in this website may include abbreviated and/or legacy terminology for HPE Aruba Networking products. See www.arubanetworks.com for current and complete HPE Aruba Networking product lines and names.
Configuring RadSec Authentication and Authorization
You can configure RadSec RadSec is an authentication and authorization protocol for transporting RADIUS datagrams over TCP and TLS. servers to authenticate HPE Aruba Networking Central On-Premises users. The RadSec protocol is used for safely transmitting the authentication and accounting data between the device and the RadSec server. For RadSec capability, you must configure the IP/hostname of the RadSec server, the server shared secret, and the authentication protocol.
To configure RadSec servers to authenticate users, complete the following steps:
- In the HPE GreenLake account home page, click .
The Manage Account page is displayed.
-
Click the Authentication card.
The Authentication tab is displayed by default.
-
Click Edit.
The Authentication Method drop-down list is displayed.
- Select RadSec from the drop-down list.
-
Click Add RadSec Server at the bottom of the page.
The Add Primary Server pop-up window is displayed.
-
Server Hostname or IP Address—Enter a specific hostname or IP address that points to the validating server.
-
Port—Enter the port number to be used.
-
Server Secret—Enter the shared secret used to access the primary RadSec server.
-
Confirm Server Secret—Re-enter the shared secret for confirmation.
-
Authentication Protocol—Select one of the following supported authentication methods to apply to both primary and secondary servers:
-
Click Add.
The Authentication page is displayed again.
-
(Optional) Click Add RadSec Server once again to configure the parameters for secondary server.
-
The authentication protocol that you selected for the primary server will be auto-populated and set as the default for the secondary server.
- If authentication fails with the primary server, the request is made to the secondary server for authentication. If both fail, the request authenticates against the default Local User Database.
-
-
Configure the secondary server parameters as described in step 6.
-
Click Add.
The Authentication page is displayed once again.
-
Click Save Changes.
The Change Authentication Method? confirmation box is displayed.
-
Click Confirm Change.
The authentication method is changed from the local user database to RadSec server.