[index] AT-TQ7403-R コマンドリファレンス 5.5.5
awplus(config)# radius-server host 172.16.10.2 key Valid8Me ↓
awplus(config)# radius-server host 172.16.10.3 auth-port 11812 acct-port 11813 key Fugafuga ↓
awplus(config)# radius-server host 172.16.10.4 timeout 10 retransmit 5 ↓
awplus(config)# no radius-server host 172.16.10.2 ↓ awplus(config)# no radius-server host 172.16.10.3 auth-port 11812 acct-port 11813 ↓
awplus# show radius ↓ RADIUS Global Configuration Source Interface : not configured Secret Key : Timeout : 5 sec Retransmit Count : 3 Deadtime : 0 min Server Host : 127.0.0.1 Authentication Port : 1812 Accounting Port : 1813 Secret Key : awplus-local-radius-server Server Host/IP Auth Acct Auth Acct Address Port Port VRF Status Status ------------------------------------------------------------------------- 127.0.0.1 1812 1813 Alive Unknown
awplus(config)# radius-server host 172.16.10.5 key himitsu5 ↓ awplus(config)# radius-server host 172.16.10.6 key himitsu6 ↓
awplus(config)# aaa authentication login default group radius ↓ awplus(config)# aaa authentication openvpn default group radius ↓ awplus(config)# aaa authentication isakmp default group radius ↓ awplus(config)# aaa authentication auth-mac default group radius ↓
awplus(config)# aaa accounting login default start-stop group radius ↓ awplus(config)# aaa accounting auth-mac default start-stop group radius ↓
NoteISAKMP認証ではアカウンティングを行えません。
ログイン認証とアカウンティング | 172.16.10.10 | himitsu10 |
172.16.10.20 | himitsu20 | |
OpenVPN認証 | 172.16.10.11 | himitsu11 |
172.16.10.21 | himitsu21 | |
ISAKMP認証 | 172.16.10.11 | himitsu11 |
MACベース認証とアカウンティング | 172.16.10.12 | himitsu12 |
172.16.10.22 | himitsu22 |
awplus(config)# radius-server host 172.16.10.10 key himitsu10 ↓ awplus(config)# radius-server host 172.16.10.11 key himitsu11 ↓ awplus(config)# radius-server host 172.16.10.12 key himitsu12 ↓ awplus(config)# radius-server host 172.16.10.20 key himitsu20 ↓ awplus(config)# radius-server host 172.16.10.21 key himitsu21 ↓ awplus(config)# radius-server host 172.16.10.22 key himitsu22 ↓
awplus(config)# aaa group server radius srv4login ↓
awplus(config-sg)# server 172.16.10.10 ↓ awplus(config-sg)# server 172.16.10.20 ↓ awplus(config-sg)# exit ↓
awplus(config)# aaa group server radius srv4openvpn ↓ awplus(config-sg)# server 172.16.10.11 ↓ awplus(config-sg)# server 172.16.10.21 ↓ awplus(config-sg)# exit ↓
awplus(config)# aaa group server radius srv4isakmp ↓ awplus(config-sg)# server 172.16.10.11 ↓ awplus(config-sg)# exit ↓
awplus(config)# aaa group server radius srv4mac ↓ awplus(config-sg)# server 172.16.10.12 ↓ awplus(config-sg)# server 172.16.10.22 ↓ awplus(config-sg)# exit ↓
awplus(config)# aaa authentication login default group srv4login ↓ awplus(config)# aaa authentication openvpn default group srv4openvpn ↓ awplus(config)# aaa authentication openvpn default group srv4isakmp ↓ awplus(config)# aaa authentication auth-mac default group srv4mac ↓
awplus(config)# aaa accounting login default start-stop group srv4login ↓ awplus(config)# aaa accounting auth-mac default start-stop group srv4mac ↓
NoteISAKMP認証ではアカウンティングを行えません。
Noteここでは、以下内容を前提として必要な最小限の設定を紹介します。なお以下の例では、RADIUSサーバーの指定を除くIPの設定は終わっているものとします。RadSecは、無線端末の認証でのみ使用可能です。
awplus(config)# crypto pki trustpoint client ↓ Created trustpoint "client". awplus(ca-trustpoint)# enrollment terminal ↓ awplus(ca-trustpoint)# end ↓ awplus# crypto pki import client pem extca_cert.pem ↓ Copying... Successful operation Subject : /O=Example Organization/CN=External CA Issuer : /O=Example Organization/CN=External CA Valid From : Aug 1 12:00:00 2018 GMT Valid To : Jan 15 12:00:00 2038 GMT Fingerprint : DDDDDDDD EEEEEEEE AAAAAAAA DDDDDDDD BBBBBBBB This is a self-signed CA certificate. The certificate has been validated successfully. Accept this certificate? (y/n): y ↓ The certificate was successfully imported.
-----BEGIN CERTIFICATE REQUEST-----
の行から-----END CERTIFICATE REQUEST-----
の行までをクリップボードにコピーしてPC上のファイル(ここでは「client_csr.pem」とします)に保存してください。awplus# crypto pki enroll client ↓ Generating 2048-bit key "server-default"... Cut and paste this request to the certificate authority: ----------------------------------------------------------------- -----BEGIN CERTIFICATE REQUEST----- MIIC0zCCAbsCAQAwQzEYMBYGA1UECgwPQWxsaWVkV2FyZSBQbHVzMScwJQYDVQQD DB5hd3BsdXMudHcuYWxsaWVkLXRlbGVzaXMuY28uanAwggEiMA0GCSqGSIb3DQEB AQUAA4IBDwAwggEKAoIBAQDP7yYzo7SRJeLLcoVpfJ8R0BhnotIDhkOS2X9t6tt5 KeiS7CZlw3rBZ9XblL4Wk0c8KdAFZAQ7LU5KMchcyRoUq4HpKcy2cO5KD1dReU27 G6OyHiuhTdDb7g5GeR3/Gn7wec398WmqHEZpqxMfjWDgE6GcLGq1kbYjnhyezIiB ivgfM+FWKkQao7hMFap4EnION/4Qi1rLG1y4ji+SBaqMaTrpIjmJajFMtrSDWhZP 371fJ04lTA9EPaLoP5QlcIRXsK/MzTv99Ifa3I5uMOogqm6Lf0HuUusNg13OUFlu gcfB8FwgGGdAjhK3dAj5XywrP8urfKkjvYjolq4UKePvAgMBAAGgSzBJBgkqhkiG 9w0BCQ4xPDA6MAkGA1UdEwQCMAAwDgYDVR0PAQH/BAQDAgWgMB0GA1UdJQQWMBQG CCsGAQUFBwMBBggrBgEFBQcDAjANBgkqhkiG9w0BAQsFAAOCAQEAIMrupXUp/f18 jgIs/mcrlkevV6YE34MGX+KP8pJyQ2mNW/3zorb4L5tc6xzZr9OvtSs4FSuaUeOB YTEMP6v/B5aBTh3csevol97DQnl/QDT5PjVkrhsO3zKqtzasV/9ozG0m/s28xRoE 4v1wQtdvBqNyxDXTZSFiR2Qu+8RInA5TvjfI/pCjVsyQggpD9i6UWICOWDwi9M9U A6Q9vTgASeejX1ac1ZERGFYUG0BzO/gwm8zjnXxBRA1i5LcL4C7JEU9jgtUbzVln lFcuC5jQJrT8a8J9ZCLomQasatQoXtp2xJz1cJXAkD+Cwg92AbQqFwzqxqF/ZBr8 IKvYIzscHQ== -----END CERTIFICATE REQUEST----- -----------------------------------------------------------------
awplus# crypto pki import client pem client_cert.pem ↓ Copying... Successful operation Subject : /O=AlliedWare Plus/CN=awplus Issuer : /O=Example Organization/CN=External CA Valid From : Jul 19 02:45:59 2022 GMT Valid To : Jul 16 02:45:59 2023 GMT Fingerprint : AAAAAAAA BBBBBBBB CCCCCCCC DDDDDDDD EEEEEEEE This is not a valid CA certificate. Attempting to import as a server certificate. The certificate has been validated successfully. ... Accept this certificate? (y/n): y ↓ The certificate was successfully imported.
awplus# configure terminal ↓ awplus(config)# radius-secure-proxy aaa ↓
awplus(config-radsecproxy-aaa)# server 10.0.0.1 name-check off ↓ awplus(config-radsecproxy-aaa)# server trustpoint client ↓ awplus(config-radsecproxy-aaa)# exit ↓
NoteRadSecの設定を行う場合、RADIUSサーバーはserverコマンドで指定してください。radius-server hostコマンドでRADIUSサーバーを指定した場合、RadSecが有効になりません。
NoteRadSecは、無線端末の認証でのみ使用可能です。
awplus# show radius-secure-proxy aaa ↓
(C) 2024-2025 アライドテレシスホールディングス株式会社
PN: 613-003360 Rev.E