NAS List

All entries

The possible options for your NAS include:

  • AccessPoints such as Meraki, OpenWiFi and Cisco;

  • Routers like Cisco, Mikrotik Router Board, pfSense, OpenWRT;

  • GGSN or PGW.

  • The AAAs from your MSO (if applicable)

  • SpherAAA as client: Your partner's AAA servers.

There is no default NAS configuration included.

Click to Configuration > NAS

NAS List

NAS List

SpherAAA RADIUS endpoint details

The NAS page shows the IP address, Authentication Port, Accounting Port and RADSEC Port that SpherAAA listens on. Use these values when you configure a NAS client or upstream AAA server to talk to SpherAAA.

MSP AAA servers

If your account is a Managed Service Provider (MSP), a separate "MSP AAA Servers" table lists the AAA servers shared across your MSP, with source address, type, environment and notes. These entries are managed by the MSP and are read-only on this page.

Enabled RADIUS clients and servers

The main table lists every configured NAS and upstream AAA server, with source/destination address, protocol, port, secret, type, environment, status and notes. Entries marked "Server" proxy or forward requests to an upstream AAA server; entries marked "Server/Client" are regular NAS clients.

The Status column shows the result of SpherAAA's health check for that entry (OK, or an error) when available.

Adding new entry

After clicking to Create, you need specify following parameters:

Nas List

New entry
  • IP Address: Enter a public IP address (NOT 192.168 OR 172.16 OR 10.*), a Network address (CIDR, eg 1.1.1.0/24) or AAA Servers IP/FQDN. For NAS clients, use the source IP or network. For AAA servers, use the destination IP or FQDN.

  • MSP AAA: (MSP accounts only) Mark this entry as an MSP AAA server. When enabled, you can set a regular expression to route requests by NAI realm (for example (.*)@(.*)), and test it against a sample realm before saving.

  • Require Message-Authenticator: Requires the Message-Authenticator attribute on all incoming requests from this NAS. This mitigates the Blast-RADIUS vulnerability.

  • Secret: Transactions between the client and RADIUS server are authenticated through the use of a shared secret, which is never sent over the network. Use "Generate Password" to create a random secret of at least 16 octets.

  • Type: Type can be used to group / classify NAS's into sub-groups. Like NAS-Type might be ResidentialAp, CafeAp, OutdoorAP, Hotspot, WLC, BRAS etc. This variable is accessible on PolicyLogic via radius.nas['Type'].

  • Environment: This Network Access Server (NAS) will utilize the assigned environment, including PolicyLogic and EAP certificates.

  • DM / CoA Port: RADIUS DM (Disconnect Message) and RADIUS CoA (Change of Authorization) is a feature that allows a RADIUS server to adjust an active client session. Default port is 3799

  • Mark as RADIUS Server: Check this mark to identify this entry as either a RADIUS or Proxy server for authentication or proxying requests.

  • Protocol: The transport protocol for this server: UDP, TCP or RADSEC.

  • Previously Imported Certificates: For RADSEC Servers, use previously imported certificates. Manage it using RADSEC Servers

  • Client Private Key: Private key file for RADSEC Client.

  • Client Certificate: Certificate file.

  • Server Root certificate: CA Certificate for RADSEC server.

  • Disable CN or SAN verification Do not validate the RADSEC server's CN or SAN with the server's IP or FQDN.

  • RADSEC Port: RADSEC Server port.

  • Note: Add description for your NAS.

Click to submit to save your changes.

Note: If you getting "Conflict NAS IP Address" error, that means you are not using public IP address of your NAS or this IP is already registered

After adding your first NAS details, you can continue configuration on your actual NAS hardware/software.

When you done on integration on your NAS, you can start adding your new users