The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Configure RADIUS authentication

Prev Next

The RADIUS server is enabled from the Manager for Sensor CLI login authentication. The Manager does not support TACACS+ and RADIUS authentication at the same time for an admin domain/device. Enabling both the authentication systems might result in conflict, and hence both might not function efficiently. A pop-up message is displayed whenever either one of the authentication system is already enabled.

  1. Navigate to Devices → <Admin Domain> → Global → Common Device Settings → Remote Access → RADIUS.

  2. Select Enable RADIUS CLI Authentication?.

    Note

    RADIUS authentication is disabled by default.

  3. Enter the details for the following fields:

    Option

    Definition

    Primary RADIUS Server

    Server IP Address

    IPv4 address of the primary RADIUS server.

    Shared Secret

    Password that is required on both the Sensor CLI and the RADIUS server. The Shared Secret is same as entered in the RADIUS server during configuration.

    Note

    The shared secret should not contain any blank spaces.

    Authentication Port (UDP)

    Port through which the primary RADIUS server communicates.

    Connection Timeout

    Time after which the session logs out automatically. You can configure the time anywhere between 2 seconds to 20 seconds.

    Enable Accounting?

    When enabled, the primary RADIUS server keeps account of the records like the current session duration and information about current data usage. This option is disabled by default.

    Accounting Port (UDP)

    Port through which the primary RADIUS server communicates to keep account.

    Secondary RADIUS Server (optional)

    Server IP Address

    IPv4 address of the secondary/backup RADIUS server.

    Shared Secret

    Password that is required on both the Sensor CLI and the RADIUS server. The Shared Secret is same as entered in the RADIUS server during configuration.

    Authentication Port (UDP)

    Port through which the secondary RADIUS server communicates.

    Connection Timeout

    Time after which the session logs out automatically. You can configure the time anywhere between 2 seconds to 20 seconds.

    Enable Accounting?

    When enabled, the secondary RADIUS server keeps account of the records like the current session duration and information about current data usage. This option is disabled by default.

    Accounting Port (UDP)

    Port through which the secondary RADIUS server communicates to keep account.

  4. Click Save to save the settings.

    Note

    In case of child domains, you can inherit the same settings using the Inherit Settings? option for RADIUS authentication.