cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
266
Views
0
Helpful
4
Replies

Radius authentication question

sarahr202
Level 5
Level 5

Hi everybody,

I am trying to learn Radius authentication . Here is my lab set up:

R1( 107.107.107.10)-------(107.107.107.4)-WIN2008(RADIUS SERVER)

Below is radius config on R1:

aaa authentication login default group radius local

radius-server host 107.107.107.4 auth-port 1645 acct-port 1646
radius-server key cisco

I have a few questions:

1) Above I do not specify any encryption on R1, what encryption will be used by R1 by default ?

In the attached file, we see password is encrypted but there is no config on R1 to use particular encryption

2) We also see " authenticator" which is I believe is R1 i.e host name encrypted with shared secret . Am I right?.

Much appreciated and have a great weekend!!

2 Accepted Solutions

Accepted Solutions

johnd2310
Level 8
Level 8

Hi,

The Radius Protocol encrypts the user-password by default. i think Radius uses MD5.

The authenticator is a random string generated by the client and is used in the process of encrypting the password.

Thanks

John

**Please rate posts you find helpful**

View solution in original post

Nadav
Level 7
Level 7

Take a look at:

http://www.untruth.org/~josh/security/radius/radius-auth.html

It'll answer both your questions fully.

View solution in original post

4 Replies 4

johnd2310
Level 8
Level 8

Hi,

The Radius Protocol encrypts the user-password by default. i think Radius uses MD5.

The authenticator is a random string generated by the client and is used in the process of encrypting the password.

Thanks

John

**Please rate posts you find helpful**

Thanks John

Nadav
Level 7
Level 7

Take a look at:

http://www.untruth.org/~josh/security/radius/radius-auth.html

It'll answer both your questions fully.

Thanks Hod for the excellent link

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: