EasyManuals Logo
Home>Cisco>Network Router>2911

Cisco 2911 Configuration Guide

Cisco 2911
408 pages
To Next Page IconTo Next Page
To Next Page IconTo Next Page
To Previous Page IconTo Previous Page
To Previous Page IconTo Previous Page
Page #317 background imageLoading...
Page #317 background image
309
Cisco 3900 Series, Cisco 2900 Series, and Cisco 1900 Series Integrated Services Routers Generation 2 Software Configuration Guide
Chapter Administering the Wireless Device
Controlling Access Point Access with RADIUS
To remove the specified RADIUS server, use the no radius-server host hostname | ip-address command
in global configuration mode. To remove a server group from the configuration list, use the no aaa group
server radius group-name command in global configuration mode. To remove the IP address of a
RADIUS server, use the no server ip-address command in sg-radius configuration mode.
In the following is example, the wireless device is configured to recognize two different RADIUS group
servers (group1 and group2). Group1 has two different host entries on the same RADIUS server which
are configured for the same services. The second host entry acts as a failover backup to the first entry.
AP(config)# aaa new-model
AP(config)# radius-server host 172.20.0.1 auth-port 1000 acct-port 1001
AP(config)# radius-server host 172.10.0.1 auth-port 1645 acct-port 1646
AP(config)# aaa group server radius group1
AP(config-sg-radius)# server 172.20.0.1 auth-port 1000 acct-port 1001
AP(config-sg-radius)# exit
AP(config)# aaa group server radius group2
AP(config-sg-radius)# server 172.20.0.1 auth-port 2000 acct-port 2001
AP(config-sg-radius)# exit
Configuring RADIUS Authorization for User Privileged Access and
Network Services
AAA authorization limits the services that are available to a user. When AAA authorization is enabled,
the wireless device uses information retrieved from the user’s profile, which is in the local user database
or on the security server, to configure the user session. The user is granted access to a requested service
only if the user profile allows it.
You can use the aaa authorization command in global configuration mode with the radius keyword to
set parameters that restrict a user’s network access to privileged EXEC mode.
The aaa authorization exec radius command sets these authorization parameters:
Use RADIUS for privileged EXEC access authorization if authentication was performed by using
RADIUS.
Use the local database if authentication was not performed by using RADIUS.
Note Authorization is bypassed for authenticated users who log in through the CLI even if authorization has
been configured.
Step 6
end Returns to privileged EXEC mode.
Step 7
show running-config Verifies your entries.
Step 8
copy running-config startup-config (Optional) Saves your entries in the configuration file.
Step 9
aaa authorization exec radius Enables RADIUS login authentication. See the “Configuring RADIUS
Login Authentication” section of the “Configuring Radius and TACACS+
Servers” chapter in Cisco IOS Software Configuration Guide for
Cisco Aironet Access Points.
Command Purpose

Table of Contents

Other manuals for Cisco 2911

Questions and Answers:

Question and Answer IconNeed help?

Do you have a question about the Cisco 2911 and is the answer not in the manual?

Cisco 2911 Specifications

General IconGeneral
Ethernet LANYes
Cabling technology10/100/1000Base-T(X)
Networking standardsIEEE 802.1Q, IEEE 802.1ag, IEEE 802.3, IEEE 802.3ab, IEEE 802.3af, IEEE 802.3ah, IEEE 802.3u
Ethernet LAN data rates10, 100, 1000 Mbit/s
Ethernet interface typeGigabit Ethernet
DHCP client-
Routing protocolsBGP, EIGRP, OSPF
Supported protocolsIPv4, IPv6, IS-IS, IGMPv3, PIM SM, SSM, DVMRP, IPSec, GRE, BVD, MPLS, L2TPv3, PPP, MLPPP, MLFR, HDLC, RS-232, RS-449, X.21, V.35, EIA-530, PPPoE, ATM
USB version2.0
RS-232 ports1
Expansion slots4 x EHWIC 2 x DSP 1 x ISM
USB ports quantity2
Ethernet LAN (RJ-45) ports3
Firewall securityCisco IOS
Input current2.2 A
AC input voltage100 - 240 V
Power source typeAC
AC input frequency47 - 63 Hz
Power consumption (typical)50 W
Product colorBlack
Rack capacity2U
Operating altitude0 - 4000 m
Non-operating altitude0 - 4570 m
Storage temperature (T-T)-40 - 80 °C
Operating temperature (T-T)0 - 40 °C
Storage relative humidity (H-H)5 - 95 %
Operating relative humidity (H-H)5 - 85 %
SafetyUL 60950-1, CAN/CSA C22.2 No. 60950-1, EN 60950-1, AS/NZS 60950-1, IEC 60950-1
Electromagnetic compatibility47 CFR, ICES-003, EN55022, CISPR22, AS/NZS 3548, VCCI V-3, EN 300-386, EN 61000, EN 55024, CISPR 24EN50082-1
Weight and Dimensions IconWeight and Dimensions
Depth304.8 mm
Width438.2 mm
Height88.9 mm
Weight8200 g

Related product manuals