A remote RADIUS server can be used for client authentication. In software release 8.0 (or newer), the RADIUS authentication and accounting servers are configured separate from the captive portal configuration. In order to perform authentication and accounting using RADIUS, you configure one or more RADIUS servers and then references the servers using their names in the captive portal configuration. Each captive portal instance can be assigned one RADIUS authentication server and one RADIUS accounting server.
If RADIUS is enabled for a captive portal configuration and no RADIUS servers are assigned, the captive portal activation status will indicate that the instance is disabled with an appropriate reason code.
The following table indicates the RADIUS attributes that are used to configure captive portal users. The table indicates both RADIUS attributes and vendor specific attributes (VSA) that are used to configure captive portal. VSAs are denoted in the ID column and are comma delimited (vendor ID, attribute ID).
| RADIUS Attribute | No. | Description | Range | Usage | Default |
| User-Name | 1 | User name to be authorized. | 1–32 characters | Required | None |
| User-Password | 2 | User password. | 8–64 characters | Required | None |
| Session-Timeout | 27 | Logout once session timeout is reached (seconds). If the attribute is 0 or not present then use the value configured for the captive portal. | Integer (seconds) | Optional | 0 |
| Idle-Timeout | 28 | Log out once idle timeout is reached (seconds). If the attribute is 0 or not present, then use the value configured for the captive portal. | Integer (seconds) | Optional | 0 |
| WISPr-Max-Bandwidth-Up | 14122, 7 | Maximum client transmit rate (b/s). Limits the bandwidth at which the client can send data into the network. If the attribute is 0 or not present, then use the value configured for the captive portal. | Integer | Optional | 0 |
| WISPr-Max-Bandwidth-Down | 14122, 8 | Maximum client receive rate (b/s). Limits the bandwidth at which the client can receive data from the network. If the attribute is 0 or not present, then use the value configured for the captive portal. | Integer | Optional | 0 |
For more information, see the following support articles:
- How do I configure Remote Authentication Dial In User Service (RADIUS) as the verification mode using CLI commands on my managed switch?
- How do I configure Remote Authentication Dial In User Service (RADIUS) as the verification mode using the web interface on my managed switch?
This article applies to the following managed switches and their respective firmware:
- M5300 - firmware version 10.0.0.x
-
- M5300-28G (GSM7228S)
- M5300-5G (GSM7252S)
- M5300-28G3 (GSM7328Sv2h2)
- M5300-52G3 (GSM7352Sv2h2)
- M5300-28G_POE+ (GSM7228PSv1h2)
- M5300-52G-POE+ (GSM7252PSv1h2)
- M5300-28GF3 (GSM7328FSv2)
- XSM7224S - firmware version 9.0.1.x