---
title: "Authenticating Using RADIUS"
canonical: "https://docs.infoblox.com/space/MAG8/912458215/Authenticating%20Using%20RADIUS"
format: markdown
---
RADIUS provides authentication, accounting, and authorization functions. The appliance supports authentication using the following RADIUS servers: FreeRADIUS, Microsoft, Cisco, and Funk.  
You must be a superuser to configure admin accounts and RADIUS server properties on the appliance.  
When you configure the appliance to authenticate administrators using a RADIUS server, the appliance acts similarly to a network access server (NAS), which is a RADIUS client that sends authentication and accounting requests to the RADIUS server.

## > Macro (anchor)

* Authentication using a RADIUS server*

> Macro (drawio)

#  > Macro (anchor)

 > Macro (anchor)

 Remote RADIUS Authentication 

When you configure the appliance for remote authentication with a RADIUS server, you must specify the authentication method of the RADIUS server. Specify PAP (Password Authentication Protocol) or CHAP (Challenge Handshake Authentication Protocol).  
PAP tries to establish the identity of a host using a two-way handshake. The client sends the user name and password in clear text to the appliance. The appliance uses a shared secret to encrypt the password and sends it to the RADIUS server in an Access-Request packet. The RADIUS server uses the shared secret to decrypt the password. If the decrypted password matches a password in its database, the user is successfully authenticated and allowed to log in.  
With CHAP, when the client tries to log in, it sends its user name and password to the appliance. The appliance then creates an MD5 hash of the password together with a random number that the appliance generates. It then sends the random number, user name, and hash to the RADIUS server in an Access-Request package. The RADIUS server takes the password that matches the user name from its database and creates its own MD5 hash of the password and random number that it received. If the hash that the RADIUS server generates matches the hash that it received from the appliance, then the user is successfully authenticated and allowed to log in.  
To configure the appliance to authenticate administrators using a RADIUS server, you must configure admin accounts and groups for these administrators on the RADIUS server. Then, on the appliance, you must do the following:

- Configure an authentication server group for RADIUS.
- Define admin groups and specify their privileges and settings. The names must match admin group names defined on the RADIUS server. The appliance applies these privileges and settings to users that belong to those groups on the RADIUS server. See [ ](https://infoblox-docs.atlassian.net/wiki/spaces/MAG8/pages/911343829)<span style="color: #0000ff">[ ](https://infoblox-docs.atlassian.net/wiki/spaces/MAG8/pages/911343829)</span>*<span style="color: #0000ff">[About](https://infoblox-docs.atlassian.net/wiki/spaces/MAG8/pages/911343829)</span>*<span style="color: #0000ff">[ ](https://infoblox-docs.atlassian.net/wiki/spaces/MAG8/pages/911343829)</span>[ ](https://infoblox-docs.atlassian.net/wiki/spaces/MAG8/pages/911343829)<span style="color: #0000ff">[ ](https://infoblox-docs.atlassian.net/wiki/spaces/MAG8/pages/911343829)</span>*<span style="color: #0000ff">[Admin](https://infoblox-docs.atlassian.net/wiki/spaces/MAG8/pages/911343829)</span>*<span style="color: #0000ff">[ ](https://infoblox-docs.atlassian.net/wiki/spaces/MAG8/pages/911343829)</span>[ ](https://infoblox-docs.atlassian.net/wiki/spaces/MAG8/pages/911343829)<span style="color: #0000ff">[ ](https://infoblox-docs.atlassian.net/wiki/spaces/MAG8/pages/911343829)</span>*<span style="color: #0000ff">[Groups](https://infoblox-docs.atlassian.net/wiki/spaces/MAG8/pages/911343829)</span>*<span style="color: #0000ff">[ ](https://infoblox-docs.atlassian.net/wiki/spaces/MAG8/pages/911343829)</span>[ ](https://infoblox-docs.atlassian.net/wiki/spaces/MAG8/pages/911343829) for information about defining admin groups.
- If there are no admin groups defined on the RADIUS server, designate an admin group as the default group. See [ ](https://infoblox-docs.atlassian.net/wiki/spaces/MAG8/pages/911343829)<span style="color: #0000ff">[ ](https://infoblox-docs.atlassian.net/wiki/spaces/MAG8/pages/911343829)</span>*<span style="color: #0000ff">[About](https://infoblox-docs.atlassian.net/wiki/spaces/MAG8/pages/911343829)</span>*<span style="color: #0000ff">[ ](https://infoblox-docs.atlassian.net/wiki/spaces/MAG8/pages/911343829)</span>[ ](https://infoblox-docs.atlassian.net/wiki/spaces/MAG8/pages/911343829)<span style="color: #0000ff">[ ](https://infoblox-docs.atlassian.net/wiki/spaces/MAG8/pages/911343829)</span>*<span style="color: #0000ff">[Admin](https://infoblox-docs.atlassian.net/wiki/spaces/MAG8/pages/911343829)</span>*<span style="color: #0000ff">[ ](https://infoblox-docs.atlassian.net/wiki/spaces/MAG8/pages/911343829)</span>[ ](https://infoblox-docs.atlassian.net/wiki/spaces/MAG8/pages/911343829)<span style="color: #0000ff">[ ](https://infoblox-docs.atlassian.net/wiki/spaces/MAG8/pages/911343829)</span>*<span style="color: #0000ff">[Groups](https://infoblox-docs.atlassian.net/wiki/spaces/MAG8/pages/911343829)</span>*<span style="color: #0000ff">[ ](https://infoblox-docs.atlassian.net/wiki/spaces/MAG8/pages/911343829)</span>[ ](https://infoblox-docs.atlassian.net/wiki/spaces/MAG8/pages/911343829) for information about defining a default admin group.
- Add the RADIUS service to the list of admin authentication services in the admin policy, and add the admin groups that match those on the RADIUS server. See [ ](https://infoblox-docs.atlassian.net/wiki/spaces/MAG8/pages/912425059)<span style="color: #0000ff">[ ](https://infoblox-docs.atlassian.net/wiki/spaces/MAG8/pages/912425059)</span>*<span style="color: #0000ff">[Defining](https://infoblox-docs.atlassian.net/wiki/spaces/MAG8/pages/912425059)</span>*<span style="color: #0000ff">[ ](https://infoblox-docs.atlassian.net/wiki/spaces/MAG8/pages/912425059)</span>[ ](https://infoblox-docs.atlassian.net/wiki/spaces/MAG8/pages/912425059)<span style="color: #0000ff">[ ](https://infoblox-docs.atlassian.net/wiki/spaces/MAG8/pages/912425059)</span>*<span style="color: #0000ff">[the](https://infoblox-docs.atlassian.net/wiki/spaces/MAG8/pages/912425059)</span>*<span style="color: #0000ff">[ ](https://infoblox-docs.atlassian.net/wiki/spaces/MAG8/pages/912425059)</span>[ ](https://infoblox-docs.atlassian.net/wiki/spaces/MAG8/pages/912425059)<span style="color: #0000ff">[ ](https://infoblox-docs.atlassian.net/wiki/spaces/MAG8/pages/912425059)</span>*<span style="color: #0000ff">[Authentication](https://infoblox-docs.atlassian.net/wiki/spaces/MAG8/pages/912425059)</span>*<span style="color: #0000ff">[ ](https://infoblox-docs.atlassian.net/wiki/spaces/MAG8/pages/912425059)</span>[ ](https://infoblox-docs.atlassian.net/wiki/spaces/MAG8/pages/912425059)<span style="color: #0000ff">[ ](https://infoblox-docs.atlassian.net/wiki/spaces/MAG8/pages/912425059)</span>*<span style="color: #0000ff">[Policy](https://infoblox-docs.atlassian.net/wiki/spaces/MAG8/pages/912425059)</span>*<span style="color: #0000ff">[ ](https://infoblox-docs.atlassian.net/wiki/spaces/MAG8/pages/912425059)</span>[ ](https://infoblox-docs.atlassian.net/wiki/spaces/MAG8/pages/912425059) for more information about configuring admin policy.

# > Macro (anchor)

 > Macro (anchor)

Configuring a RADIUS Authentication Server Group

You can add multiple RADIUS servers to the group for redundancy. When you do, the appliance tries to connect to the first RADIUS server on the list and if the server does not respond within the maximum retransmission limit, then it tries the next RADIUS server on the list.  
After you add a RADIUS server to the appliance, you can validate the configuration. The appliance uses a pre-defined username and password when it tests the connection to the RADIUS server. The pre-defined user name is "Infoblox_test_user" and the password is "Infoblox_test_password". Do not use these as your administrator username and password.  
To configure a RADIUS authentication server group on the appliance:

> Macro (legacy-content)

# > Macro (anchor)

 > Macro (anchor)

Managing the RADIUS Server List

When you add multiple RADIUS servers, the appliance lists the servers in the order you added them. This list also determines the order in which the appliance attempts to contact a RADIUS server. You can change the order of the list, as follows:

1. From the **Administration** tab, click the **Authentication** **Server** **Groups** tab -> **RADIUS** **Services** subtab, select the *server_group* checkbox and click the Edit icon.
2. In the *RADIUS** Servers* table, do the following:
  - To move a server up the list, select it and click the up arrow.
  - To move a server down the list, select it and click the down arrow.  
You can also delete a RADIUS server by selecting a RADIUS server from the RADIUS Servers table and clicking the Delete icon.
3. Save the configuration.

# > Macro (anchor)

 > Macro (anchor)

Disabling RADIUS Servers on Multi-Grid Master

You can disable a RADIUS server if, for example, the connection to the server is down and you want to stop the appliance from trying to connect to this server.  
To disable a RADIUS server:

1. From the **Administration** tab, click the **Authentication** **Server** **Groups** tab -> **RADIUS** **Services** subtab, select the *server_group* checkbox and click the Edit icon.
2. In the *RADIUS* *Service* editor, select the checkbox of the server you want to disable in the RADIUS Servers section, and then click the Edit icon.
3. In the RADIUS Servers section, select **Disable**.
4. Save the configuration.

# > Macro (anchor)

 > Macro (anchor)

Configuring Remote RADIUS Servers

In addition to setting up the appliance to communicate with a RADIUS server, you must also set up the remote RADIUS server to communicate with the appliance.

---

**Note:** If you have two Infoblox appliances in an HA pair, enter both the members of the HA pair as separate access appliances and use the LAN or MGMT IP address of both appliances (not the VIP address), if configured.

---

Depending on your particular RADIUS server, you can configure the following RADIUS server options to enable communication with the appliance:

- Authentication Port
- Accounting Port
- Domain Name/IP Address of the appliance
- Shared Secret Password
- Vendor Types

## Configuring Admin Groups on the Remote RADIUS Server

Infoblox supports admin accounts on one or more RADIUS servers.  
To set up admins and associate them with an admin group on a remote RADIUS server, do the following:

- Import Infoblox VSAs (vendor-specific attributes) to the dictionary file on the RADIUS server
- For third-party RADIUS servers, import the Infoblox vendor file (the Infoblox vendor ID is 7779)
- Define a local admin group on the appliance (or use an existing group)
- Define a remote admin group—with the same name as the group defined on the appliance—on the RADIUS server
- Associate one or more remote admin accounts on the RADIUS server with the remote admin group Refer to the documentation for your RADIUS server for more information.

## Configuring Admin Accounts on the Remote RADIUS Server

To set up remote admin accounts on a RADIUS server and apply the privileges and properties of the admin group on the appliance, do the following:

> Macro (legacy-content)

When an administrator whose account is stored on a RADIUS server attempts to log in to a appliance, the appliance forwards the user name and password for authentication to the RADIUS server. When the server successfully authenticates the administrator and it responds to the appliance without specifying an admin group, the appliance applies the privileges and properties of the default admin group to that administrator. Refer to the documentation for your RADIUS server for more information.

# > Macro (anchor)

 > Macro (anchor)

Authorization Groups Using RADIUS

You can specify authorization privileges for an admin group on the appliance only. The appliance ignores authorization settings from the RADIUS server. Therefore, you must configure all admin groups on the appliance, regardless of where the admin accounts that belong to those groups are stored—on the appliance or on the RADIUS server. For information about specifying superuser and limited-access authorization privileges, see [ ](https://infoblox-docs.atlassian.net/wiki/spaces/MAG8/pages/911343829/About+Admin+Groups#AboutAdminGroups-bookmark157)<span style="color: #0000ff">[ ](https://infoblox-docs.atlassian.net/wiki/spaces/MAG8/pages/911343829/About+Admin+Groups#AboutAdminGroups-bookmark157)</span>*<span style="color: #0000ff">[Creating](https://infoblox-docs.atlassian.net/wiki/spaces/MAG8/pages/911343829/About+Admin+Groups#AboutAdminGroups-bookmark157)</span>*<span style="color: #0000ff">[ ](https://infoblox-docs.atlassian.net/wiki/spaces/MAG8/pages/911343829/About+Admin+Groups#AboutAdminGroups-bookmark157)</span>[ ](https://infoblox-docs.atlassian.net/wiki/spaces/MAG8/pages/911343829/About+Admin+Groups#AboutAdminGroups-bookmark157) [ ](https://infoblox-docs.atlassian.net/wiki/spaces/MAG8/pages/911343829/About+Admin+Groups#AboutAdminGroups-bookmark157)<span style="color: #0000ff">[ ](https://infoblox-docs.atlassian.net/wiki/spaces/MAG8/pages/911343829/About+Admin+Groups#AboutAdminGroups-bookmark157)</span>*<span style="color: #0000ff">[Superuser](https://infoblox-docs.atlassian.net/wiki/spaces/MAG8/pages/911343829/About+Admin+Groups#AboutAdminGroups-bookmark157)</span>*<span style="color: #0000ff">[ ](https://infoblox-docs.atlassian.net/wiki/spaces/MAG8/pages/911343829/About+Admin+Groups#AboutAdminGroups-bookmark157)</span>[ ](https://infoblox-docs.atlassian.net/wiki/spaces/MAG8/pages/911343829/About+Admin+Groups#AboutAdminGroups-bookmark157)<span style="color: #0000ff">[ ](https://infoblox-docs.atlassian.net/wiki/spaces/MAG8/pages/911343829/About+Admin+Groups#AboutAdminGroups-bookmark157)</span>*<span style="color: #0000ff">[Admin](https://infoblox-docs.atlassian.net/wiki/spaces/MAG8/pages/911343829/About+Admin+Groups#AboutAdminGroups-bookmark157)</span>*<span style="color: #0000ff">[ ](https://infoblox-docs.atlassian.net/wiki/spaces/MAG8/pages/911343829/About+Admin+Groups#AboutAdminGroups-bookmark157)</span>[ ](https://infoblox-docs.atlassian.net/wiki/spaces/MAG8/pages/911343829/About+Admin+Groups#AboutAdminGroups-bookmark157)<span style="color: #0000ff">[ ](https://infoblox-docs.atlassian.net/wiki/spaces/MAG8/pages/911343829/About+Admin+Groups#AboutAdminGroups-bookmark157)</span>*<span style="color: #0000ff">[Groups](https://infoblox-docs.atlassian.net/wiki/spaces/MAG8/pages/911343829/About+Admin+Groups#AboutAdminGroups-bookmark157)</span>*<span style="color: #0000ff">[ ](https://infoblox-docs.atlassian.net/wiki/spaces/MAG8/pages/911343829/About+Admin+Groups#AboutAdminGroups-bookmark157)</span>[ ](https://infoblox-docs.atlassian.net/wiki/spaces/MAG8/pages/911343829/About+Admin+Groups#AboutAdminGroups-bookmark157) and [ ](https://infoblox-docs.atlassian.net/wiki/spaces/MAG8/pages/911343829/About+Admin+Groups#AboutAdminGroups-bookmark159)<span style="color: #0000ff">[ ](https://infoblox-docs.atlassian.net/wiki/spaces/MAG8/pages/911343829/About+Admin+Groups#AboutAdminGroups-bookmark159)</span>*<span style="color: #0000ff">[Creating](https://infoblox-docs.atlassian.net/wiki/spaces/MAG8/pages/911343829/About+Admin+Groups#AboutAdminGroups-bookmark159)</span>*<span style="color: #0000ff">[ ](https://infoblox-docs.atlassian.net/wiki/spaces/MAG8/pages/911343829/About+Admin+Groups#AboutAdminGroups-bookmark159)</span>[ ](https://infoblox-docs.atlassian.net/wiki/spaces/MAG8/pages/911343829/About+Admin+Groups#AboutAdminGroups-bookmark159)<span style="color: #0000ff">[ ](https://infoblox-docs.atlassian.net/wiki/spaces/MAG8/pages/911343829/About+Admin+Groups#AboutAdminGroups-bookmark159)</span>*<span style="color: #0000ff">[Limited-Access](https://infoblox-docs.atlassian.net/wiki/spaces/MAG8/pages/911343829/About+Admin+Groups#AboutAdminGroups-bookmark159)</span>*<span style="color: #0000ff">[ ](https://infoblox-docs.atlassian.net/wiki/spaces/MAG8/pages/911343829/About+Admin+Groups#AboutAdminGroups-bookmark159)</span>[ ](https://infoblox-docs.atlassian.net/wiki/spaces/MAG8/pages/911343829/About+Admin+Groups#AboutAdminGroups-bookmark159)<span style="color: #0000ff">[ ](https://infoblox-docs.atlassian.net/wiki/spaces/MAG8/pages/911343829/About+Admin+Groups#AboutAdminGroups-bookmark159)</span>*<span style="color: #0000ff">[Admin](https://infoblox-docs.atlassian.net/wiki/spaces/MAG8/pages/911343829/About+Admin+Groups#AboutAdminGroups-bookmark159)</span>*<span style="color: #0000ff">[ ](https://infoblox-docs.atlassian.net/wiki/spaces/MAG8/pages/911343829/About+Admin+Groups#AboutAdminGroups-bookmark159)</span>[ ](https://infoblox-docs.atlassian.net/wiki/spaces/MAG8/pages/911343829/About+Admin+Groups#AboutAdminGroups-bookmark159)<span style="color: #0000ff">[ ](https://infoblox-docs.atlassian.net/wiki/spaces/MAG8/pages/911343829/About+Admin+Groups#AboutAdminGroups-bookmark159)</span>*<span style="color: #0000ff">[Groups](https://infoblox-docs.atlassian.net/wiki/spaces/MAG8/pages/911343829/About+Admin+Groups#AboutAdminGroups-bookmark159)</span>*.  
Then you must add those admin groups to the authentication policy. For more information, see [ ](https://infoblox-docs.atlassian.net/wiki/spaces/MAG8/pages/912425059)<span style="color: #0000ff">[ ](https://infoblox-docs.atlassian.net/wiki/spaces/MAG8/pages/912425059)</span>*<span style="color: #0000ff">[Defining](https://infoblox-docs.atlassian.net/wiki/spaces/MAG8/pages/912425059)</span>*<span style="color: #0000ff">[ ](https://infoblox-docs.atlassian.net/wiki/spaces/MAG8/pages/912425059)</span>[ ](https://infoblox-docs.atlassian.net/wiki/spaces/MAG8/pages/912425059)<span style="color: #0000ff">[ ](https://infoblox-docs.atlassian.net/wiki/spaces/MAG8/pages/912425059)</span>*<span style="color: #0000ff">[the](https://infoblox-docs.atlassian.net/wiki/spaces/MAG8/pages/912425059)</span>*<span style="color: #0000ff">[ ](https://infoblox-docs.atlassian.net/wiki/spaces/MAG8/pages/912425059)</span>[ ](https://infoblox-docs.atlassian.net/wiki/spaces/MAG8/pages/912425059) [ ](https://infoblox-docs.atlassian.net/wiki/spaces/MAG8/pages/912425059)<span style="color: #0000ff">[ ](https://infoblox-docs.atlassian.net/wiki/spaces/MAG8/pages/912425059)</span>*<span style="color: #0000ff">[Authentication](https://infoblox-docs.atlassian.net/wiki/spaces/MAG8/pages/912425059)</span>*<span style="color: #0000ff">[ ](https://infoblox-docs.atlassian.net/wiki/spaces/MAG8/pages/912425059)</span>[ ](https://infoblox-docs.atlassian.net/wiki/spaces/MAG8/pages/912425059)<span style="color: #0000ff">[ ](https://infoblox-docs.atlassian.net/wiki/spaces/MAG8/pages/912425059)</span>*<span style="color: #0000ff">[Policy](https://infoblox-docs.atlassian.net/wiki/spaces/MAG8/pages/912425059)</span>*.

# > Macro (anchor)

 > Macro (anchor)

Accounting Activities Using RADIUS

You can enable the accounting feature on the RADIUS server to track whether an administrator has initiated a session. After an administrator successfully logs in, the appliance sends an Accounting-Start packet to the RADIUS server.