Explains how Cisco IOS XR redirects RADIUS packets to a remote server over TLS so AAA traffic receives encrypted transport and peer protection.
A RADIUS TLS protection is a secure transport mechanism that
-
protects RADIUS packets by using TLS between the Cisco IOS XR RADIUS client and a remote RADIUS server
-
reduces exposure to data disclosure, replay attacks, weak authentication, and encryption weaknesses, and
-
supports TLS version 1.3.
Feature history
|
Feature Name |
Release Information |
Feature Description |
|---|---|---|
|
RADIUS with TLS protection |
Release 26.2.1 |
Introduced in this release on: Centralized Systems (8400 [ASIC: K100])(select variants only*) *This feature is now supported on Cisco 8404-SYS-D routers. |
|
RADIUS with TLS protection |
Release 24.4.1 |
Remote Authentication Dial-In User Service (RADIUS) packets are now less vulnerable to security risks, including data exposure, replay attacks, weak authentication, and encryption weaknesses. This is because we have enabled support for RADIUS with TLS protection. You can configure the RADIUS protocol on the router to redirect RADIUS packets to a remote server over TLS for Authentication, Authorization, and Accounting (AAA) services. The feature introduces these changes: CLI:
YANG Data Models:
(see GitHub, YANG Data Models Navigator) |